Anda di halaman 1dari 633

pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:EssentialInit, log:"Start of d

iagnostic log for process with command line: \"C:\Users\i92segoa\Desktop\Firefox


SEO\firefox.exe\" , current pid: 0xFFC"
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:EssentialInit, log:"Done Setti
ng some windows apis. Time consumed so far: 0 ms."
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:_DetermineOS, log:"OS Informat
ion - Version 10.0.10586, SP: 0.0, Suite: 0x300, Platform: 0x2, ProductType: 0x1
, Text: ."
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:EssentialInit, log:"Got OS inf
o. Time consumed so far: 0 ms."
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:EssentialInit, log:"Virtual En
vironment is 32bit"
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:EssentialInit, log:"Got parent
info. Time consumed so far: 0 ms."
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:Init, log:"@APPDIR@ = C:\Users
\i92segoa\Desktop\Firefox SEO"
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:EssentialInit, log:"Initialize
d folder mapper. Time consumed so far: 0 ms."
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:_LoadBootstrapSettings, log:"L
oading bootstrap settings."
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:_LoadBootstrapSettings, log:"D
one loading bootstrap settings."
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:EssentialInit, log:"Applicatio
n executing with VM version: 11.8.723"
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:_LoadApplicationSvmSettings, l
og:"Loading embedded app settings."
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:FinalInit, log:"@WINDIR@ = C:\
WINDOWS"
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:FinalInit, log:"@SYSDRIVE@ = C
:"
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:FinalInit, log:"@PROGRAMFILES@
= C:\Program Files"
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:FinalInit, log:"@PROGRAMFILESC
OMMON@ = C:\Program Files\Common Files"
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:FinalInit, log:"@PROGRAMFILESX
86@ = C:\Program Files (x86)"
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:FinalInit, log:"@PROGRAMFILESC
OMMONX86@ = C:\Program Files (x86)\Common Files"
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:FinalInit, log:"@SYSTEM@ = C:\
WINDOWS\system32"
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:FinalInit, log:"@SYSWOW64@ = C
:\WINDOWS\SysWOW64"
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:FinalInit, log:"@SYSNATIVE@ =
C:\WINDOWS\Sysnative"
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:FinalInit, log:"@PROFILE@ = C:
\Users\i92segoa"
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:FinalInit, log:"@PROFILECOMMON
@ = C:\ProgramData"
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:FinalInit, log:"@APPDATA@ = C:
\Users\i92segoa\AppData\Roaming"
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:FinalInit, log:"@APPDATALOCAL@
= C:\Users\i92segoa\AppData\Local"
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:FinalInit, log:"@APPDATALOCALL
OW@ = C:\Users\i92segoa\AppData\LocalLow"
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:FinalInit, log:"@STARTMENU@ =
C:\Users\i92segoa\AppData\Roaming\Microsoft\Windows\Start Menu"
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:FinalInit, log:"@PROGRAMS@ = C
:\Users\i92segoa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs"
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:FinalInit, log:"@STARTUP@ = C:
\Users\i92segoa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup"

pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:FinalInit, log:"@TEMPLATES@ =


C:\Users\i92segoa\AppData\Roaming\Microsoft\Windows\Templates"
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:FinalInit, log:"@FAVORITES@ =
C:\Users\i92segoa\Favorites"
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:FinalInit, log:"@DESKTOP@ = C:
\Users\i92segoa\Desktop"
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:FinalInit, log:"@DOCUMENTS@ =
C:\Users\i92segoa\Documents"
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:FinalInit, log:"@MUSIC@ = C:\U
sers\i92segoa\Music"
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:FinalInit, log:"@PICTURES@ = C
:\Users\i92segoa\Pictures"
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:FinalInit, log:"@VIDEOS@ = C:\
Users\i92segoa\Videos"
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:FinalInit, log:"@APPDATACOMMON
@ = C:\ProgramData"
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:FinalInit, log:"@STARTMENUCOMM
ON@ = C:\ProgramData\Microsoft\Windows\Start Menu"
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:FinalInit, log:"@PROGRAMSCOMMO
N@ = C:\ProgramData\Microsoft\Windows\Start Menu\Programs"
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:FinalInit, log:"@STARTUPCOMMON
@ = C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup"
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:FinalInit, log:"@DESKTOPCOMMON
@ = C:\Users\Public\Desktop"
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:FinalInit, log:"@TEMPLATESCOMM
ON@ = C:\ProgramData\Microsoft\Windows\Templates"
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:FinalInit, log:"@FAVORITESCOMM
ON@ = C:\Users\i92segoa\Favorites"
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:FinalInit, log:"@DOCUMENTSCOMM
ON@ = C:\Users\Public\Documents"
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:FinalInit, log:"@MUSICCOMMON@
= C:\Users\Public\Music"
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:FinalInit, log:"@PICTURESCOMMO
N@ = C:\Users\Public\Pictures"
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:FinalInit, log:"Got raw folder
s. Time consumed so far: 0 ms."
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \??\C: to \Device\HarddiskVolume2"
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \??\C:\WINDOWS\system32 to \Device\HarddiskVolume2\Windows\Sy
sWOW64"
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \??\C:\WINDOWS\Sysnative to \Device\HarddiskVolume2\Windows\S
ystem32"
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\USER\S-1-5-18 to \REGISTRY\USER\.DEFAULT"
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001
_Classes\CLSID to \REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\
SOFTWARE\CLASSES\Wow6432Node\CLSID"
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001
\SOFTWARE\CLASSES\CLSID to \REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990
887-1001\SOFTWARE\CLASSES\Wow6432Node\CLSID"
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001
\SOFTWARE\Wow6432Node\CLASSES\CLSID to \REGISTRY\USER\S-1-5-21-2360094602-260238
3397-2463990887-1001\SOFTWARE\CLASSES\Wow6432Node\CLSID"
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001

_Classes\DirectShow to \REGISTRY\USER\S-1-5-21-2360094602-2602383397-24639908871001\SOFTWARE\CLASSES\Wow6432Node\DirectShow"
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001
\SOFTWARE\CLASSES\DirectShow to \REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\SOFTWARE\CLASSES\Wow6432Node\DirectShow"
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001
\SOFTWARE\Wow6432Node\CLASSES\DirectShow to \REGISTRY\USER\S-1-5-21-2360094602-2
602383397-2463990887-1001\SOFTWARE\CLASSES\Wow6432Node\DirectShow"
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001
_Classes\Interface to \REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1
001\SOFTWARE\CLASSES\Wow6432Node\Interface"
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001
\SOFTWARE\CLASSES\Interface to \REGISTRY\USER\S-1-5-21-2360094602-2602383397-246
3990887-1001\SOFTWARE\CLASSES\Wow6432Node\Interface"
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001
\SOFTWARE\Wow6432Node\CLASSES\Interface to \REGISTRY\USER\S-1-5-21-2360094602-26
02383397-2463990887-1001\SOFTWARE\CLASSES\Wow6432Node\Interface"
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001
_Classes\Media Type to \REGISTRY\USER\S-1-5-21-2360094602-2602383397-24639908871001\SOFTWARE\CLASSES\Wow6432Node\Media Type"
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001
\SOFTWARE\CLASSES\Media Type to \REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\SOFTWARE\CLASSES\Wow6432Node\Media Type"
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001
\SOFTWARE\Wow6432Node\CLASSES\Media Type to \REGISTRY\USER\S-1-5-21-2360094602-2
602383397-2463990887-1001\SOFTWARE\CLASSES\Wow6432Node\Media Type"
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001
_Classes\MediaFoundation to \REGISTRY\USER\S-1-5-21-2360094602-2602383397-246399
0887-1001\SOFTWARE\CLASSES\Wow6432Node\MediaFoundation"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001
\SOFTWARE\CLASSES\MediaFoundation to \REGISTRY\USER\S-1-5-21-2360094602-26023833
97-2463990887-1001\SOFTWARE\CLASSES\Wow6432Node\MediaFoundation"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001
\SOFTWARE\Wow6432Node\CLASSES\MediaFoundation to \REGISTRY\USER\S-1-5-21-2360094
602-2602383397-2463990887-1001\SOFTWARE\CLASSES\Wow6432Node\MediaFoundation"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\RegisteredApplications to \REGISTR
Y\MACHINE\SOFTWARE\RegisteredApplications"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\RegisteredApplications
to \REGISTRY\MACHINE\SOFTWARE\RegisteredApplications"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Policies to \REGISTRY\MACHINE\SOFT
WARE\Policies"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Policies to \REGISTRY\
MACHINE\SOFTWARE\Policies"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersio

n\Time Zones to \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\T


ime Zones"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\C
urrentVersion\Time Zones to \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\Curr
entVersion\Time Zones"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersio
n\ProfileList to \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\
ProfileList"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\C
urrentVersion\ProfileList to \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\Cur
rentVersion\ProfileList"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersio
n\Print to \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\C
urrentVersion\Print to \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVe
rsion\Print"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersio
n\Ports to \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Ports"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\C
urrentVersion\Ports to \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVe
rsion\Ports"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersio
n\Perflib to \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perf
lib"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\C
urrentVersion\Perflib to \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\Current
Version\Perflib"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersio
n\NetworkCards to \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\NetworkCards"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\C
urrentVersion\NetworkCards to \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\Cu
rrentVersion\NetworkCards"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersio
n\FontSubstitutes to \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVers
ion\FontSubstitutes"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\C
urrentVersion\FontSubstitutes to \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT
\CurrentVersion\FontSubstitutes"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersio
n\Fonts to \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\C
urrentVersion\Fonts to \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVe
rsion\Fonts"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding

alias mapping from \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersio


n\FontMapper to \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\F
ontMapper"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\C
urrentVersion\FontMapper to \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\Curr
entVersion\FontMapper"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersio
n\FontDpi to \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Font
Dpi"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\C
urrentVersion\FontDpi to \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\Current
Version\FontDpi"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\T
elephony\Locations to \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersio
n\Telephony\Locations"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Curr
entVersion\Telephony\Locations to \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\C
urrentVersion\Telephony\Locations"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\S
etup to \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Curr
entVersion\Setup to \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
Setup"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\P
olicies to \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Curr
entVersion\Policies to \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersi
on\Policies"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\G
roup Policy to \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Group
Policy"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Curr
entVersion\Group Policy to \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentV
ersion\Group Policy"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\C
ontrol Panel\Cursors\Schemes to \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\Cur
rentVersion\Control Panel\Cursors\Schemes"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Curr
entVersion\Control Panel\Cursors\Schemes to \REGISTRY\MACHINE\SOFTWARE\Microsoft
\Windows\CurrentVersion\Control Panel\Cursors\Schemes"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Microsoft\Transaction Server to \R
EGISTRY\MACHINE\SOFTWARE\Microsoft\Transaction Server"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Transaction
Server to \REGISTRY\MACHINE\SOFTWARE\Microsoft\Transaction Server"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding

alias mapping from \REGISTRY\MACHINE\SOFTWARE\Microsoft\TermServLicensing to \RE


GISTRY\MACHINE\SOFTWARE\Microsoft\TermServLicensing"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\TermServLice
nsing to \REGISTRY\MACHINE\SOFTWARE\Microsoft\TermServLicensing"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Microsoft\SystemCertificates to \R
EGISTRY\MACHINE\SOFTWARE\Microsoft\SystemCertificates"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\SystemCertif
icates to \REGISTRY\MACHINE\SOFTWARE\Microsoft\SystemCertificates"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Microsoft\SOFTWARE\Microsoft\Share
d Tools\MSInfo to \REGISTRY\MACHINE\SOFTWARE\Microsoft\SOFTWARE\Microsoft\Shared
Tools\MSInfo"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\SOFTWARE\Mic
rosoft\Shared Tools\MSInfo to \REGISTRY\MACHINE\SOFTWARE\Microsoft\SOFTWARE\Micr
osoft\Shared Tools\MSInfo"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Microsoft\RPC to \REGISTRY\MACHINE
\SOFTWARE\Microsoft\RPC"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\RPC to \REGI
STRY\MACHINE\SOFTWARE\Microsoft\RPC"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Microsoft\RAS to \REGISTRY\MACHINE
\SOFTWARE\Microsoft\RAS"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\RAS to \REGI
STRY\MACHINE\SOFTWARE\Microsoft\RAS"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Microsoft\OLE to \REGISTRY\MACHINE
\SOFTWARE\Microsoft\OLE"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\OLE to \REGI
STRY\MACHINE\SOFTWARE\Microsoft\OLE"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Microsoft\Non-Driver Signing to \R
EGISTRY\MACHINE\SOFTWARE\Microsoft\Non-Driver Signing"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Non-Driver S
igning to \REGISTRY\MACHINE\SOFTWARE\Microsoft\Non-Driver Signing"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Microsoft\MSMQ to \REGISTRY\MACHIN
E\SOFTWARE\Microsoft\MSMQ"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\MSMQ to \REG
ISTRY\MACHINE\SOFTWARE\Microsoft\MSMQ"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Microsoft\EventSystem to \REGISTRY
\MACHINE\SOFTWARE\Microsoft\EventSystem"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\EventSystem
to \REGISTRY\MACHINE\SOFTWARE\Microsoft\EventSystem"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates t
o \REGISTRY\MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\EnterpriseCe

rtificates to \REGISTRY\MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Microsoft\Driver Signing to \REGIS
TRY\MACHINE\SOFTWARE\Microsoft\Driver Signing"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Driver Signi
ng to \REGISTRY\MACHINE\SOFTWARE\Microsoft\Driver Signing"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Microsoft\DFS to \REGISTRY\MACHINE
\SOFTWARE\Microsoft\DFS"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\DFS to \REGI
STRY\MACHINE\SOFTWARE\Microsoft\DFS"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Microsoft\CTF\TIP to \REGISTRY\MAC
HINE\SOFTWARE\Microsoft\CTF\TIP"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\CTF\TIP to \
REGISTRY\MACHINE\SOFTWARE\Microsoft\CTF\TIP"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Microsoft\CTF\SystemShared to \REG
ISTRY\MACHINE\SOFTWARE\Microsoft\CTF\SystemShared"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\CTF\SystemSh
ared to \REGISTRY\MACHINE\SOFTWARE\Microsoft\CTF\SystemShared"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Microsoft\Cryptography\Services to
\REGISTRY\MACHINE\SOFTWARE\Microsoft\Cryptography\Services"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography
\Services to \REGISTRY\MACHINE\SOFTWARE\Microsoft\Cryptography\Services"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Microsoft\Cryptography\Calais\Read
ers to \REGISTRY\MACHINE\SOFTWARE\Microsoft\Cryptography\Calais\Readers"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography
\Calais\Readers to \REGISTRY\MACHINE\SOFTWARE\Microsoft\Cryptography\Calais\Read
ers"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Microsoft\Cryptography\Calais\Curr
ent to \REGISTRY\MACHINE\SOFTWARE\Microsoft\Cryptography\Calais\Current"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography
\Calais\Current to \REGISTRY\MACHINE\SOFTWARE\Microsoft\Cryptography\Calais\Curr
ent"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Microsoft\COM3 to \REGISTRY\MACHIN
E\SOFTWARE\Microsoft\COM3"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\COM3 to \REG
ISTRY\MACHINE\SOFTWARE\Microsoft\COM3"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Classes\MediaFoundation to \REGIST
RY\MACHINE\SOFTWARE\Classes\Wow6432Node\MediaFoundation"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Classes\MediaFoundatio
n to \REGISTRY\MACHINE\SOFTWARE\Classes\Wow6432Node\MediaFoundation"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Classes\Wow6432Node\MediaFoundatio
n to \REGISTRY\MACHINE\SOFTWARE\Classes\Wow6432Node\MediaFoundation"

pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding


alias mapping from \REGISTRY\MACHINE\SOFTWARE\Classes\Media Type to \REGISTRY\MA
CHINE\SOFTWARE\Classes\Wow6432Node\Media Type"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Classes\Media Type to
\REGISTRY\MACHINE\SOFTWARE\Classes\Wow6432Node\Media Type"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Classes\Wow6432Node\Media Type to
\REGISTRY\MACHINE\SOFTWARE\Classes\Wow6432Node\Media Type"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Classes\Interface to \REGISTRY\MAC
HINE\SOFTWARE\Classes\Wow6432Node\Interface"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Classes\Interface to \
REGISTRY\MACHINE\SOFTWARE\Classes\Wow6432Node\Interface"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Classes\Wow6432Node\Interface to \
REGISTRY\MACHINE\SOFTWARE\Classes\Wow6432Node\Interface"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Classes\DirectShow to \REGISTRY\MA
CHINE\SOFTWARE\Classes\Wow6432Node\DirectShow"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Classes\DirectShow to
\REGISTRY\MACHINE\SOFTWARE\Classes\Wow6432Node\DirectShow"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Classes\Wow6432Node\DirectShow to
\REGISTRY\MACHINE\SOFTWARE\Classes\Wow6432Node\DirectShow"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Classes\CLSID to \REGISTRY\MACHINE
\SOFTWARE\Classes\Wow6432Node\CLSID"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID to \REGI
STRY\MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID to \REGI
STRY\MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Classes\Wow6432Node to \REGISTRY\M
ACHINE\SOFTWARE\Classes"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Classes to \REGISTRY\MACHINE\SOFTW
ARE\Classes"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Classes to \REGISTRY\M
ACHINE\SOFTWARE\Classes"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Wow6432Node to \REGISTRY\MACHINE\S
OFTWARE\Wow6432Node"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE to \REGISTRY\MACHINE\SOFTWARE\Wow6
432Node"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001
_Classes to \REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWA
RE\CLASSES"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:FinalInit, log:"Got alternativ
e paths. Time consumed so far: 16 ms."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_LoadItem, log:"Skipping confi
g type: 0x2E"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_LoadItem, log:"Skipping confi

g type: 0x32"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_LoadItem, log:"Skipping confi
g type: 0x28"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_LoadApplicationSvmSettings, l
og:"Done loading embedded app settings."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_LoadBootstrapSystemLayer, log
:"Loading embedded system layers."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_LoadItem, log:"Skipping confi
g type: 0x2E"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_LoadItem, log:"Skipping confi
g type: 0x32"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_LoadItem, log:"Skipping confi
g type: 0x28"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_LoadLayer, log:"Loading inner
layer: Xenocode"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @APPDATA@ (at \Device\HarddiskVolume2\Users\i92segoa\AppDat
a\Roaming) with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @APPDATACOMMON@ (at \Device\HarddiskVolume2\ProgramData) wi
th flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @APPDATALOCAL@ (at \Device\HarddiskVolume2\Users\i92segoa\A
ppData\Local) with flags: 8C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @APPDATALOCALLOW@ (at \Device\HarddiskVolume2\Users\i92sego
a\AppData\LocalLow) with flags: 8C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @APPDIR@ (at \Device\HarddiskVolume2\Users\i92segoa\Desktop
\Firefox SEO) with flags: 4."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @DESKTOP@ (at \Device\HarddiskVolume2\Users\i92segoa\Deskto
p) with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @DESKTOPCOMMON@ (at \Device\HarddiskVolume2\Users\Public\De
sktop) with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @DOCUMENTS@ (at \Device\HarddiskVolume2\Users\i92segoa\Docu
ments) with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @DOCUMENTSCOMMON@ (at \Device\HarddiskVolume2\Users\Public\
Documents) with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @FAVORITES@ (at \Device\HarddiskVolume2\Users\i92segoa\Favo
rites) with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @FAVORITESCOMMON@ (at \Device\HarddiskVolume2\Users\i92sego
a\Favorites) with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @MUSIC@ (at \Device\HarddiskVolume2\Users\i92segoa\Music) w
ith flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @MUSICCOMMON@ (at \Device\HarddiskVolume2\Users\Public\Musi
c) with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @PICTURES@ (at \Device\HarddiskVolume2\Users\i92segoa\Pictu
res) with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @PICTURESCOMMON@ (at \Device\HarddiskVolume2\Users\Public\P
ictures) with flags: C."

pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A


dding root directory @PROFILE@ (at \Device\HarddiskVolume2\Users\i92segoa) with
flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @PROFILECOMMON@ (at \Device\HarddiskVolume2\ProgramData) wi
th flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @PROGRAMFILES@ (at \Device\HarddiskVolume2\Program Files) w
ith flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @PROGRAMFILESCOMMON@ (at \Device\HarddiskVolume2\Program Fi
les\Common Files) with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @PROGRAMFILESCOMMONX86@ (at \Device\HarddiskVolume2\Program
Files (x86)\Common Files) with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @PROGRAMFILESX86@ (at \Device\HarddiskVolume2\Program Files
(x86)) with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @PROGRAMS@ (at \Device\HarddiskVolume2\Users\i92segoa\AppDa
ta\Roaming\Microsoft\Windows\Start Menu\Programs) with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @PROGRAMSCOMMON@ (at \Device\HarddiskVolume2\ProgramData\Mi
crosoft\Windows\Start Menu\Programs) with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @STARTMENU@ (at \Device\HarddiskVolume2\Users\i92segoa\AppD
ata\Roaming\Microsoft\Windows\Start Menu) with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @STARTMENUCOMMON@ (at \Device\HarddiskVolume2\ProgramData\M
icrosoft\Windows\Start Menu) with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @STARTUP@ (at \Device\HarddiskVolume2\Users\i92segoa\AppDat
a\Roaming\Microsoft\Windows\Start Menu\Programs\Startup) with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @STARTUPCOMMON@ (at \Device\HarddiskVolume2\ProgramData\Mic
rosoft\Windows\Start Menu\Programs\Startup) with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @SYSDRIVE@ (at \Device\HarddiskVolume2) with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"S
kipping special directory root @SYSTEM@"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @SYSWOW64@ (at \Device\HarddiskVolume2\WINDOWS\SysWOW64) wi
th flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @TEMPLATES@ (at \Device\HarddiskVolume2\Users\i92segoa\AppD
ata\Roaming\Microsoft\Windows\Templates) with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @TEMPLATESCOMMON@ (at \Device\HarddiskVolume2\ProgramData\M
icrosoft\Windows\Templates) with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @VIDEOS@ (at \Device\HarddiskVolume2\Users\i92segoa\Videos)
with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @WINDIR@ (at \Device\HarddiskVolume2\WINDOWS) with flags: C
."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_LoadComplexItemCore, log:"Ski
pping config type: 0x12"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_LoadComplexItemCore, log:"Ski
pping config type: 0x15"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_LoadBootstrapSystemLayer, log

:"Done loading embedded system layerss."


pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_LoadApplicationSvmNonSystemLa
yers, log:"Loading embedded app xlayer."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_LoadItem, log:"Skipping confi
g type: 0x2E"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_LoadItem, log:"Skipping confi
g type: 0x32"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_LoadItem, log:"Skipping confi
g type: 0x28"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_LoadLayer, log:"Loading inner
layer: Default"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @APPDATA@ (at \Device\HarddiskVolume2\Users\i92segoa\AppDat
a\Roaming) with flags: 4."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @APPDATACOMMON@ (at \Device\HarddiskVolume2\ProgramData) wi
th flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @APPDATALOCAL@ (at \Device\HarddiskVolume2\Users\i92segoa\A
ppData\Local) with flags: 84."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @APPDATALOCALLOW@ (at \Device\HarddiskVolume2\Users\i92sego
a\AppData\LocalLow) with flags: 84."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @APPDIR@ (at \Device\HarddiskVolume2\Users\i92segoa\Desktop
\Firefox SEO) with flags: 4."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @DESKTOP@ (at \Device\HarddiskVolume2\Users\i92segoa\Deskto
p) with flags: 4."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @DESKTOPCOMMON@ (at \Device\HarddiskVolume2\Users\Public\De
sktop) with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @DOCUMENTS@ (at \Device\HarddiskVolume2\Users\i92segoa\Docu
ments) with flags: 4."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @DOCUMENTSCOMMON@ (at \Device\HarddiskVolume2\Users\Public\
Documents) with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @FAVORITES@ (at \Device\HarddiskVolume2\Users\i92segoa\Favo
rites) with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @FAVORITESCOMMON@ (at \Device\HarddiskVolume2\Users\i92sego
a\Favorites) with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @MUSIC@ (at \Device\HarddiskVolume2\Users\i92segoa\Music) w
ith flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @MUSICCOMMON@ (at \Device\HarddiskVolume2\Users\Public\Musi
c) with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @PICTURES@ (at \Device\HarddiskVolume2\Users\i92segoa\Pictu
res) with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @PICTURESCOMMON@ (at \Device\HarddiskVolume2\Users\Public\P
ictures) with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @PROFILE@ (at \Device\HarddiskVolume2\Users\i92segoa) with
flags: 4."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A

dding root directory @PROFILECOMMON@ (at \Device\HarddiskVolume2\ProgramData) wi


th flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @PROGRAMFILES@ (at \Device\HarddiskVolume2\Program Files) w
ith flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @PROGRAMFILESCOMMON@ (at \Device\HarddiskVolume2\Program Fi
les\Common Files) with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @PROGRAMFILESCOMMONX86@ (at \Device\HarddiskVolume2\Program
Files (x86)\Common Files) with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @PROGRAMFILESX86@ (at \Device\HarddiskVolume2\Program Files
(x86)) with flags: 4."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @PROGRAMS@ (at \Device\HarddiskVolume2\Users\i92segoa\AppDa
ta\Roaming\Microsoft\Windows\Start Menu\Programs) with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @PROGRAMSCOMMON@ (at \Device\HarddiskVolume2\ProgramData\Mi
crosoft\Windows\Start Menu\Programs) with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @STARTMENU@ (at \Device\HarddiskVolume2\Users\i92segoa\AppD
ata\Roaming\Microsoft\Windows\Start Menu) with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @STARTMENUCOMMON@ (at \Device\HarddiskVolume2\ProgramData\M
icrosoft\Windows\Start Menu) with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @STARTUP@ (at \Device\HarddiskVolume2\Users\i92segoa\AppDat
a\Roaming\Microsoft\Windows\Start Menu\Programs\Startup) with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @STARTUPCOMMON@ (at \Device\HarddiskVolume2\ProgramData\Mic
rosoft\Windows\Start Menu\Programs\Startup) with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @SYSDRIVE@ (at \Device\HarddiskVolume2) with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"S
kipping special directory root @SYSTEM@"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @SYSWOW64@ (at \Device\HarddiskVolume2\WINDOWS\SysWOW64) wi
th flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @TEMPLATES@ (at \Device\HarddiskVolume2\Users\i92segoa\AppD
ata\Roaming\Microsoft\Windows\Templates) with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @TEMPLATESCOMMON@ (at \Device\HarddiskVolume2\ProgramData\M
icrosoft\Windows\Templates) with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @VIDEOS@ (at \Device\HarddiskVolume2\Users\i92segoa\Videos)
with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @WINDIR@ (at \Device\HarddiskVolume2\WINDOWS) with flags: 4
."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_LoadComplexItemCore, log:"Ski
pping config type: 0x12"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_LoadComplexItemCore, log:"Ski
pping config type: 0x15"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \??\C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\
Start Menu\Programs\StartUp to \Device\HarddiskVolume2\Users\i92segoa\AppData\Ro
aming\Microsoft\Windows\Start Menu\Programs\Startup"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding

alias mapping from \??\C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\


Start Menu\Programs to \Device\HarddiskVolume2\Users\i92segoa\AppData\Roaming\Mi
crosoft\Windows\Start Menu\Programs"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \??\C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\
Start Menu to \Device\HarddiskVolume2\Users\i92segoa\AppData\Roaming\Microsoft\W
indows\Start Menu"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \??\C:\Users\Administrator\Desktop to \Device\HarddiskVolume2
\Users\i92segoa\Desktop"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \??\C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\
Templates to \Device\HarddiskVolume2\Users\i92segoa\AppData\Roaming\Microsoft\Wi
ndows\Templates"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \??\C:\Users\Administrator\Favorites to \Device\HarddiskVolum
e2\Users\i92segoa\Favorites"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \??\C:\Users\Administrator\Music to \Device\HarddiskVolume2\U
sers\i92segoa\Music"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \??\C:\Users\Administrator\Pictures to \Device\HarddiskVolume
2\Users\i92segoa\Pictures"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \??\C:\Users\Administrator\Documents to \Device\HarddiskVolum
e2\Users\i92segoa\Documents"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \??\C:\Users\Administrator\AppData\Local to \Device\HarddiskV
olume2\Users\i92segoa\AppData\Local"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \??\C:\Users\Administrator\AppData\Roaming to \Device\Harddis
kVolume2\Users\i92segoa\AppData\Roaming"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \??\C:\Users\Administrator to \Device\HarddiskVolume2\Users\i
92segoa"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \??\C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Star
tUp to \Device\HarddiskVolume2\ProgramData\Microsoft\Windows\Start Menu\Programs
\Startup"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \??\C:\ProgramData\Microsoft\Windows\Start Menu\Programs to \
Device\HarddiskVolume2\ProgramData\Microsoft\Windows\Start Menu\Programs"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \??\C:\ProgramData\Microsoft\Windows\Start Menu to \Device\Ha
rddiskVolume2\ProgramData\Microsoft\Windows\Start Menu"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \??\C:\Users\Public\Desktop to \Device\HarddiskVolume2\Users\
Public\Desktop"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \??\C:\ProgramData\Microsoft\Windows\Templates to \Device\Har
ddiskVolume2\ProgramData\Microsoft\Windows\Templates"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \??\C:\Users\Public\Music to \Device\HarddiskVolume2\Users\Pu
blic\Music"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \??\C:\Users\Public\Pictures to \Device\HarddiskVolume2\Users
\Public\Pictures"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \??\C:\Users\Public\Documents to \Device\HarddiskVolume2\User
s\Public\Documents"

pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding


alias mapping from \??\C:\ProgramData to \Device\HarddiskVolume2\ProgramData"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \??\C:\Program Files (x86)\Common Files to \Device\HarddiskVo
lume2\Program Files (x86)\Common Files"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \??\C:\Program Files (x86) to \Device\HarddiskVolume2\Program
Files (x86)"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \??\C:\Windows\SysWOW64 to \Device\HarddiskVolume2\WINDOWS\Sy
sWOW64"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \??\C:\Windows to \Device\HarddiskVolume2\WINDOWS"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_LoadLayer, log:"Loading inner
layer: Flash||14.0.0.125||1||Default"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @APPDATA@ (at \Device\HarddiskVolume2\Users\i92segoa\AppDat
a\Roaming) with flags: 4."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @APPDATACOMMON@ (at \Device\HarddiskVolume2\ProgramData) wi
th flags: 4."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @APPDATALOCAL@ (at \Device\HarddiskVolume2\Users\i92segoa\A
ppData\Local) with flags: 84."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @APPDATALOCALLOW@ (at \Device\HarddiskVolume2\Users\i92sego
a\AppData\LocalLow) with flags: 8C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @APPDIR@ (at \Device\HarddiskVolume2\Users\i92segoa\Desktop
\Firefox SEO) with flags: 4."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @DESKTOP@ (at \Device\HarddiskVolume2\Users\i92segoa\Deskto
p) with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @DESKTOPCOMMON@ (at \Device\HarddiskVolume2\Users\Public\De
sktop) with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @DOCUMENTS@ (at \Device\HarddiskVolume2\Users\i92segoa\Docu
ments) with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @DOCUMENTSCOMMON@ (at \Device\HarddiskVolume2\Users\Public\
Documents) with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @FAVORITES@ (at \Device\HarddiskVolume2\Users\i92segoa\Favo
rites) with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @FAVORITESCOMMON@ (at \Device\HarddiskVolume2\Users\i92sego
a\Favorites) with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @MUSIC@ (at \Device\HarddiskVolume2\Users\i92segoa\Music) w
ith flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @MUSICCOMMON@ (at \Device\HarddiskVolume2\Users\Public\Musi
c) with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @PICTURES@ (at \Device\HarddiskVolume2\Users\i92segoa\Pictu
res) with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @PICTURESCOMMON@ (at \Device\HarddiskVolume2\Users\Public\P
ictures) with flags: C."

pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A


dding root directory @PROFILE@ (at \Device\HarddiskVolume2\Users\i92segoa) with
flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @PROFILECOMMON@ (at \Device\HarddiskVolume2\ProgramData) wi
th flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @PROGRAMFILES@ (at \Device\HarddiskVolume2\Program Files) w
ith flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @PROGRAMFILESCOMMON@ (at \Device\HarddiskVolume2\Program Fi
les\Common Files) with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @PROGRAMFILESCOMMONX86@ (at \Device\HarddiskVolume2\Program
Files (x86)\Common Files) with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @PROGRAMFILESX86@ (at \Device\HarddiskVolume2\Program Files
(x86)) with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @PROGRAMS@ (at \Device\HarddiskVolume2\Users\i92segoa\AppDa
ta\Roaming\Microsoft\Windows\Start Menu\Programs) with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @PROGRAMSCOMMON@ (at \Device\HarddiskVolume2\ProgramData\Mi
crosoft\Windows\Start Menu\Programs) with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @STARTMENU@ (at \Device\HarddiskVolume2\Users\i92segoa\AppD
ata\Roaming\Microsoft\Windows\Start Menu) with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @STARTMENUCOMMON@ (at \Device\HarddiskVolume2\ProgramData\M
icrosoft\Windows\Start Menu) with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @STARTUP@ (at \Device\HarddiskVolume2\Users\i92segoa\AppDat
a\Roaming\Microsoft\Windows\Start Menu\Programs\Startup) with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @STARTUPCOMMON@ (at \Device\HarddiskVolume2\ProgramData\Mic
rosoft\Windows\Start Menu\Programs\Startup) with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @SYSDRIVE@ (at \Device\HarddiskVolume2) with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"S
kipping special directory root @SYSTEM@"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @SYSWOW64@ (at \Device\HarddiskVolume2\WINDOWS\SysWOW64) wi
th flags: 4."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @TEMPLATES@ (at \Device\HarddiskVolume2\Users\i92segoa\AppD
ata\Roaming\Microsoft\Windows\Templates) with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @TEMPLATESCOMMON@ (at \Device\HarddiskVolume2\ProgramData\M
icrosoft\Windows\Templates) with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @VIDEOS@ (at \Device\HarddiskVolume2\Users\i92segoa\Videos)
with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @WINDIR@ (at \Device\HarddiskVolume2\WINDOWS) with flags: 4
."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_LoadComplexItemCore, log:"Ski
pping config type: 0x12"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_LoadComplexItemCore, log:"Ski
pping config type: 0x15"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_LoadItem, log:"Skipping confi

g type: 0x17"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \??\C:\Program Files\Common Files to \Device\HarddiskVolume2\
Program Files (x86)\Common Files"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \??\C:\Program Files to \Device\HarddiskVolume2\Program Files
(x86)"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_LoadApplicationSvmNonSystemLa
yers, log:"Done loading embedded app xlayer."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding directory Downloads with flags: 14."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding directory __Xenocode with flags: 3."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"D
uplicate directory __Xenocode will not be added as it is at lower layer."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"D
uplicate directory __Xenocode will not be added as it is at lower layer."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:FormatSandboxPath, log:"Settin
g sandbox path to: \Device\HarddiskVolume2\Users\i92segoa\Desktop\Firefox SEO\da
ta"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding directory Google with flags: 4."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding directory Mozilla with flags: 6."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding directory Adobe with flags: A."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding directory Macromedia with flags: A."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:FormatSandboxPath, log:"Settin
g registry cache path to: \REGISTRY\USER\S-1-5-21-2360094602-2602383397-24639908
87-1001\Software\Spoon\SandboxCache\A527E666CB0D6807"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding directory XSxS with flags: 2."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"D
uplicate directory XSxS will not be added as it is at lower layer."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding directory Mozilla Firefox with flags: 2."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:EssentialInit, log:"Extracted
configuration. Time consumed so far: 16 ms."
pid:4092, tid:2168, tick:0x33D6F92, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x670000, zerobits:0x0, commitsize:0x0, offset:0x210000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6F92, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5B0000
pid:4092, tid:2168, tick:0x33D6F92, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x570000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6F92, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x670000
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding directory Macromed with flags: 2."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:NtOpenSection, status:0xC00000
34, handle:0x0, access:0xF, path:"\KnownDlls32\Iphlpapi.dll"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseRegistryConfig, log:"Du
plicate regkey Software will not be added as it is at lower layer."
pid:4092, tid:2168, tick:0x33D6F92, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x580000, zerobits:0x0, commitsize:0x0, offset:0x220000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6F92, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x570000

pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseRegistryConfig, log:"Du


plicate regkey SOFTWARE will not be added as it is at lower layer."
pid:4092, tid:2168, tick:0x33D6F92, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x570000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6F92, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x580000
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseRegistryConfig, log:"Du
plicate regkey SOFTWARE will not be added as it is at lower layer."
pid:4092, tid:2168, tick:0x33D6F92, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x580000, zerobits:0x0, commitsize:0x0, offset:0x270000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6F92, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x570000
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseRegistryConfig, log:"Du
plicate regkey SYSTEM will not be added as it is at lower layer."
pid:4092, tid:2168, tick:0x33D6F92, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x570000, zerobits:0x0, commitsize:0x0, offset:0x220000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6F92, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x580000
pid:4092, tid:2168, tick:0x33D6F92, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x580000, zerobits:0x0, commitsize:0x0, offset:0x270000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6F92, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x570000
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseRegistryConfig, log:"Du
plicate regkey CurrentControlSet will not be added as it is at lower layer."
pid:4092, tid:2168, tick:0x33D6F92, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x570000, zerobits:0x0, commitsize:0x0, offset:0x220000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6F92, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x580000
pid:4092, tid:2168, tick:0x33D6F92, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x580000, zerobits:0x0, commitsize:0x0, offset:0x270000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6F92, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x570000
pid:4092, tid:2168, tick:0x33D6F92, lvl:OK, func:NtOpenKey, status:0x0, handle:0
xD8, access:0x1, path:"\Registry\MACHINE\System\CurrentControlSet\Control\Sessio
n Manager"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"SafeDllSearchMode", class:0x2, length:0x10, resultlength:0x681B54, h
andle:0xD8, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\SESSION MANAGER
"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:NtQueryAttributesFile, status:
0xC0000034, path:"C:\Users\i92segoa\Desktop\Firefox SEO\Iphlpapi.dll"
pid:4092, tid:2168, tick:0x33D6F92, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x20, path:"C:\WINDOWS\SYSTEM32\Iphlpapi.dll"
pid:4092, tid:2168, tick:0x33D6F92, lvl:OK, func:NtOpenFile, status:0x0, handle:
0xDC, access:0x100021, iostatus:0x0, information:0x1, share:0x5, options:0x60, p
ath:"C:\WINDOWS\SYSTEM32\Iphlpapi.dll"
pid:4092, tid:2168, tick:0x33D6F92, lvl:OK, func:NtCreateSection, status:0x0, ha
ndle:0xE0, access:0xF, pageattribs:0x10, sectionattribs:0x1000000, file:0xDC
pid:4092, tid:2168, tick:0x33D6F92, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x736A0000, zerobits:0x0, commitsize:0x0, viewsize:0x2F000, disposition
:0x1, type:0x800000, protect:0x4, handle:0xE0, path:"C:\WINDOWS\SYSTEM32\Iphlpap
i.dll"
pid:4092, tid:2168, tick:0x33D6F92, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"Iphlpapi.dll", handle:0x736A0000

pid:4092, tid:2168, tick:0x33D6F92, lvl:OK, func:LdrGetDllHandle, status:0x0, na


me:"ntdll.dll", module:0x77C10000
pid:4092, tid:2168, tick:0x33D6F92, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"ntdll.dll", module:0x77C10000
pid:4092, tid:2168, tick:0x33D6F92, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"ntdll.dll", module:0x77C10000
pid:4092, tid:2168, tick:0x33D6F92, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"ntdll.dll", module:0x77C10000
pid:4092, tid:2168, tick:0x33D6F92, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"ntdll.dll", module:0x77C10000
pid:4092, tid:2168, tick:0x33D6F92, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"ntdll.dll", module:0x77C10000
pid:4092, tid:2168, tick:0x33D6F92, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"ntdll.dll", module:0x77C10000
pid:4092, tid:2168, tick:0x33D6F92, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"ntdll.dll", module:0x77C10000
pid:4092, tid:2168, tick:0x33D6F92, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"ntdll.dll", module:0x77C10000
pid:4092, tid:2168, tick:0x33D6F92, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"kernel32.dll", module:0x74CD0000
pid:4092, tid:2168, tick:0x33D6F92, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"kernel32.dll", module:0x74CD0000
pid:4092, tid:2168, tick:0x33D6FA1, lvl:LOG, func:_WrapExistingHandles, log:"Wra
pping existing handles"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:LOG, func:_WrapExistingHandles, log:" W
rapping File handle: 0x14."
pid:4092, tid:2168, tick:0x33D6FA1, lvl:LOG, func:_WrapExistingHandles, log:" W
rapping Key handle: 0x1C."
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x570000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x580000
pid:4092, tid:2168, tick:0x33D6FA1, lvl:LOG, func:RecurseRegistryConfig, log:"Du
plicate regkey Classes will not be added as it is at lower layer."
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x580000, zerobits:0x0, commitsize:0x0, offset:0x220000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x570000
pid:4092, tid:2168, tick:0x33D6FA1, lvl:LOG, func:RecurseRegistryConfig, log:"Du
plicate regkey CLASSES will not be added as it is at lower layer."
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x570000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x580000
pid:4092, tid:2168, tick:0x33D6FA1, lvl:LOG, func:RecurseRegistryConfig, log:"Du
plicate regkey Classes will not be added as it is at lower layer."
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x580000, zerobits:0x0, commitsize:0x0, offset:0x270000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x570000
pid:4092, tid:2168, tick:0x33D6FA1, lvl:LOG, func:RecurseRegistryConfig, log:"Du
plicate regkey Wow6432Node will not be added as it is at lower layer."
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x570000, zerobits:0x0, commitsize:0x0, offset:0x220000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtUnmapViewOfSection, status:0x

0, address:0x580000
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x580000, zerobits:0x0, commitsize:0x0, offset:0x270000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x570000
pid:4092, tid:2168, tick:0x33D6FA1, lvl:LOG, func:RecurseRegistryConfig, log:"Du
plicate regkey Microsoft will not be added as it is at lower layer."
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x570000, zerobits:0x0, commitsize:0x0, offset:0x220000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x580000
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x580000, zerobits:0x0, commitsize:0x0, offset:0x270000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x570000
pid:4092, tid:2168, tick:0x33D6FA1, lvl:LOG, func:RecurseRegistryConfig, log:"Du
plicate regkey Windows will not be added as it is at lower layer."
pid:4092, tid:2168, tick:0x33D6FA1, lvl:LOG, func:_WrapExistingHandles, log:" W
rapping File handle: 0x28."
pid:4092, tid:2168, tick:0x33D6FA1, lvl:LOG, func:_WrapExistingHandles, log:" W
rapping Key handle: 0x6C."
pid:4092, tid:2168, tick:0x33D6FA1, lvl:LOG, func:_WrapExistingHandles, log:" W
rapping Key handle: 0x70."
pid:4092, tid:2168, tick:0x33D6FA1, lvl:LOG, func:_WrapExistingHandles, log:" W
rapping Key handle: 0x74."
pid:4092, tid:2168, tick:0x33D6FA1, lvl:LOG, func:_WrapExistingHandles, log:" W
rapping File handle: 0x84."
pid:4092, tid:2168, tick:0x33D6FA1, lvl:LOG, func:_WrapExistingHandles, log:" W
rapping Key handle: 0xA4."
pid:4092, tid:2168, tick:0x33D6FA1, lvl:LOG, func:_WrapExistingHandles, log:" W
rapping Key handle: 0xD8."
pid:4092, tid:2168, tick:0x33D6FA1, lvl:LOG, func:_WrapExistingHandles, log:" W
rapping File handle: 0xDC."
pid:4092, tid:2168, tick:0x33D6FA1, lvl:LOG, func:_WrapExistingHandles, log:" W
rapping File handle: 0xF0."
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x570000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x580000
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x580000, zerobits:0x0, commitsize:0x0, offset:0x220000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x570000
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x570000, zerobits:0x0, commitsize:0x0, offset:0x270000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x580000
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x580000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x570000
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x570000, zerobits:0x0, commitsize:0x0, offset:0x210000, viewsize:0x100

00, disposition:0x2, type:0x0, protect:0x2, handle:0x78


pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x580000
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x580000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x570000
pid:4092, tid:2168, tick:0x33D6FA1, lvl:LOG, func:RecurseRegistryConfig, log:"Du
plicate regkey Software will not be added as it is at lower layer."
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtCreateKey, status:0x0, handle
:0x160, access:0xF013F, title:0x0, options:0x0, path:"\REGISTRY\USER\S-1-5-21-23
60094602-2602383397-2463990887-1001\Environment"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtSetValueKey, status:0x0, name
:"path", index:0x0, type:0x2, size:0x64C, handle:0x160, path:"\REGISTRY\USER\S-1
-5-21-2360094602-2602383397-2463990887-1001\Environment"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtClose, status:0x0, handle:0x1
60
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtOpenFile, status:0x0, handle:
0x1D0, access:0x100020, iostatus:0x0, information:0x0, share:0x3, options:0x21,
path:"C:\Users\i92segoa\Desktop\Firefox SEO\"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtQueryVolumeInformationFile, s
tatus:0x0, iostatus:0x0, information:0x8, length:0x8, class:0x4, handle:0x1D0, p
ath:"C:\Users\i92segoa\Desktop\Firefox SEO"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtClose, status:0x0, handle:0x2
8
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x570000, zerobits:0x0, commitsize:0x0, offset:0x220000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x580000
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x28, access:0x20119, path:"\REGISTRY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x0, class:0x0, length:0x400, resultlength:0x30, handle:0x28, path:"\REGISTRY
\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1, class:0x0, length:0x400, resultlength:0x32, handle:0x28, path:"\REGISTRY
\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x2, class:0x0, length:0x400, resultlength:0x3E, handle:0x28, path:"\REGISTRY
\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x3, class:0x0, length:0x400, resultlength:0x4E, handle:0x28, path:"\REGISTRY
\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x4, class:0x0, length:0x400, resultlength:0x52, handle:0x28, path:"\REGISTRY
\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x5, class:0x0, length:0x400, resultlength:0x58, handle:0x28, path:"\REGISTRY
\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x6, class:0x0, length:0x400, resultlength:0x42, handle:0x28, path:"\REGISTRY
\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x7, class:0x0, length:0x400, resultlength:0x32, handle:0x28, path:"\REGISTRY
\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x8, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGISTRY
\MACHINE\System\CurrentControlSet\Services"

pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind


ex:0x9, class:0x0, length:0x400, resultlength:0x22, handle:0x28, path:"\REGISTRY
\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xA, class:0x0, length:0x400, resultlength:0x20, handle:0x28, path:"\REGISTRY
\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xB, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGISTRY
\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xC, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGISTRY
\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xD, class:0x0, length:0x400, resultlength:0x26, handle:0x28, path:"\REGISTRY
\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xE, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGISTRY
\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xF, class:0x0, length:0x400, resultlength:0x36, handle:0x28, path:"\REGISTRY
\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x10, class:0x0, length:0x400, resultlength:0x32, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x11, class:0x0, length:0x400, resultlength:0x26, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x12, class:0x0, length:0x400, resultlength:0x20, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x13, class:0x0, length:0x400, resultlength:0x1E, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x14, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x15, class:0x0, length:0x400, resultlength:0x26, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x16, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x17, class:0x0, length:0x400, resultlength:0x1E, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x18, class:0x0, length:0x400, resultlength:0x22, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x19, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1A, class:0x0, length:0x400, resultlength:0x26, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1B, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1C, class:0x0, length:0x400, resultlength:0x26, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"

pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind


ex:0x1D, class:0x0, length:0x400, resultlength:0x2C, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1E, class:0x0, length:0x400, resultlength:0x2E, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1F, class:0x0, length:0x400, resultlength:0x22, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x20, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x21, class:0x0, length:0x400, resultlength:0x26, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x22, class:0x0, length:0x400, resultlength:0x30, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x23, class:0x0, length:0x400, resultlength:0x26, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x24, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x25, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x26, class:0x0, length:0x400, resultlength:0x22, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x27, class:0x0, length:0x400, resultlength:0x20, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x28, class:0x0, length:0x400, resultlength:0x1E, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x29, class:0x0, length:0x400, resultlength:0x40, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x2A, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x2B, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x2C, class:0x0, length:0x400, resultlength:0x26, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x2D, class:0x0, length:0x400, resultlength:0x30, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x2E, class:0x0, length:0x400, resultlength:0x2E, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x2F, class:0x0, length:0x400, resultlength:0x22, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x30, class:0x0, length:0x400, resultlength:0x22, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"

pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind


ex:0x31, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x32, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x33, class:0x0, length:0x400, resultlength:0x20, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x34, class:0x0, length:0x400, resultlength:0x1E, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x35, class:0x0, length:0x400, resultlength:0x20, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x36, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x37, class:0x0, length:0x400, resultlength:0x40, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x38, class:0x0, length:0x400, resultlength:0x26, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x39, class:0x0, length:0x400, resultlength:0x2C, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x3A, class:0x0, length:0x400, resultlength:0x2A, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x3B, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x3C, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x3D, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x3E, class:0x0, length:0x400, resultlength:0x26, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x3F, class:0x0, length:0x400, resultlength:0x26, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x40, class:0x0, length:0x400, resultlength:0x36, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x41, class:0x0, length:0x400, resultlength:0x38, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x42, class:0x0, length:0x400, resultlength:0x2A, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x43, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x44, class:0x0, length:0x400, resultlength:0x20, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"

pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind


ex:0x45, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x46, class:0x0, length:0x400, resultlength:0x22, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x47, class:0x0, length:0x400, resultlength:0x2E, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x48, class:0x0, length:0x400, resultlength:0x2C, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x49, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x4A, class:0x0, length:0x400, resultlength:0x20, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x4B, class:0x0, length:0x400, resultlength:0x32, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x4C, class:0x0, length:0x400, resultlength:0x26, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x4D, class:0x0, length:0x400, resultlength:0x54, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x4E, class:0x0, length:0x400, resultlength:0x54, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x4F, class:0x0, length:0x400, resultlength:0x54, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x50, class:0x0, length:0x400, resultlength:0x54, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x51, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x52, class:0x0, length:0x400, resultlength:0x1E, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x53, class:0x0, length:0x400, resultlength:0x2E, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x54, class:0x0, length:0x400, resultlength:0x30, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x55, class:0x0, length:0x400, resultlength:0x2A, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x56, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x57, class:0x0, length:0x400, resultlength:0x44, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x58, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"

pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind


ex:0x59, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x5A, class:0x0, length:0x400, resultlength:0x3A, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x5B, class:0x0, length:0x400, resultlength:0x3A, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x5C, class:0x0, length:0x400, resultlength:0x20, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x5D, class:0x0, length:0x400, resultlength:0x26, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x5E, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x5F, class:0x0, length:0x400, resultlength:0x1E, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x60, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x61, class:0x0, length:0x400, resultlength:0x2A, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x62, class:0x0, length:0x400, resultlength:0x1E, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x63, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x64, class:0x0, length:0x400, resultlength:0x2A, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x65, class:0x0, length:0x400, resultlength:0x2C, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x66, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x67, class:0x0, length:0x400, resultlength:0x2A, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x68, class:0x0, length:0x400, resultlength:0x48, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x69, class:0x0, length:0x400, resultlength:0x32, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x6A, class:0x0, length:0x400, resultlength:0x34, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x6B, class:0x0, length:0x400, resultlength:0x20, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x6C, class:0x0, length:0x400, resultlength:0x2C, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"

pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind


ex:0x6D, class:0x0, length:0x400, resultlength:0x20, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x6E, class:0x0, length:0x400, resultlength:0x68, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x6F, class:0x0, length:0x400, resultlength:0x2A, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x70, class:0x0, length:0x400, resultlength:0x20, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x71, class:0x0, length:0x400, resultlength:0x36, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x72, class:0x0, length:0x400, resultlength:0x22, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x73, class:0x0, length:0x400, resultlength:0x38, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x74, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x75, class:0x0, length:0x400, resultlength:0x22, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x76, class:0x0, length:0x400, resultlength:0x26, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x77, class:0x0, length:0x400, resultlength:0x1E, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x78, class:0x0, length:0x400, resultlength:0x26, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x79, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x7A, class:0x0, length:0x400, resultlength:0x22, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x7B, class:0x0, length:0x400, resultlength:0x26, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x7C, class:0x0, length:0x400, resultlength:0x26, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x7D, class:0x0, length:0x400, resultlength:0x22, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x7E, class:0x0, length:0x400, resultlength:0x1E, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x7F, class:0x0, length:0x400, resultlength:0x2E, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x80, class:0x0, length:0x400, resultlength:0x30, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"

pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind


ex:0x81, class:0x0, length:0x400, resultlength:0x30, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x82, class:0x0, length:0x400, resultlength:0x2A, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x83, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x84, class:0x0, length:0x400, resultlength:0x22, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x85, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x86, class:0x0, length:0x400, resultlength:0x2E, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x87, class:0x0, length:0x400, resultlength:0x22, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x88, class:0x0, length:0x400, resultlength:0x26, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x89, class:0x0, length:0x400, resultlength:0x1E, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x8A, class:0x0, length:0x400, resultlength:0x1E, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x8B, class:0x0, length:0x400, resultlength:0x26, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x8C, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x8D, class:0x0, length:0x400, resultlength:0x2E, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x8E, class:0x0, length:0x400, resultlength:0x22, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x8F, class:0x0, length:0x400, resultlength:0x2A, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x90, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x91, class:0x0, length:0x400, resultlength:0x2A, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x92, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x93, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x94, class:0x0, length:0x400, resultlength:0x2A, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"

pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind


ex:0x95, class:0x0, length:0x400, resultlength:0x38, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x96, class:0x0, length:0x400, resultlength:0x2A, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x97, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x98, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x99, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x9A, class:0x0, length:0x400, resultlength:0x2E, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x9B, class:0x0, length:0x400, resultlength:0x2C, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x9C, class:0x0, length:0x400, resultlength:0x30, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x9D, class:0x0, length:0x400, resultlength:0x3E, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x9E, class:0x0, length:0x400, resultlength:0x2E, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x9F, class:0x0, length:0x400, resultlength:0x22, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xA0, class:0x0, length:0x400, resultlength:0x30, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xA1, class:0x0, length:0x400, resultlength:0x26, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xA2, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xA3, class:0x0, length:0x400, resultlength:0x36, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xA4, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xA5, class:0x0, length:0x400, resultlength:0x26, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xA6, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xA7, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xA8, class:0x0, length:0x400, resultlength:0x30, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"

pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind


ex:0xA9, class:0x0, length:0x400, resultlength:0x22, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xAA, class:0x0, length:0x400, resultlength:0x26, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xAB, class:0x0, length:0x400, resultlength:0x2A, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xAC, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xAD, class:0x0, length:0x400, resultlength:0x3A, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xAE, class:0x0, length:0x400, resultlength:0x3A, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xAF, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xB0, class:0x0, length:0x400, resultlength:0x20, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xB1, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xB2, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xB3, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xB4, class:0x0, length:0x400, resultlength:0x22, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xB5, class:0x0, length:0x400, resultlength:0x20, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xB6, class:0x0, length:0x400, resultlength:0x30, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xB7, class:0x0, length:0x400, resultlength:0x30, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xB8, class:0x0, length:0x400, resultlength:0x2E, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xB9, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xBA, class:0x0, length:0x400, resultlength:0x26, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xBB, class:0x0, length:0x400, resultlength:0x22, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xBC, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"

pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind


ex:0xBD, class:0x0, length:0x400, resultlength:0x42, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xBE, class:0x0, length:0x400, resultlength:0x20, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xBF, class:0x0, length:0x400, resultlength:0x42, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xC0, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xC1, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xC2, class:0x0, length:0x400, resultlength:0x42, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xC3, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xC4, class:0x0, length:0x400, resultlength:0x2A, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xC5, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xC6, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xC7, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xC8, class:0x0, length:0x400, resultlength:0x22, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xC9, class:0x0, length:0x400, resultlength:0x34, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xCA, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xCB, class:0x0, length:0x400, resultlength:0x26, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xCC, class:0x0, length:0x400, resultlength:0x22, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xCD, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xCE, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xCF, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xD0, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"

pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind


ex:0xD1, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xD2, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xD3, class:0x0, length:0x400, resultlength:0x22, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xD4, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xD5, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xD6, class:0x0, length:0x400, resultlength:0x26, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xD7, class:0x0, length:0x400, resultlength:0x26, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xD8, class:0x0, length:0x400, resultlength:0x22, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xD9, class:0x0, length:0x400, resultlength:0x30, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xDA, class:0x0, length:0x400, resultlength:0x3A, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xDB, class:0x0, length:0x400, resultlength:0x20, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xDC, class:0x0, length:0x400, resultlength:0x22, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xDD, class:0x0, length:0x400, resultlength:0x34, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xDE, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xDF, class:0x0, length:0x400, resultlength:0x26, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xE0, class:0x0, length:0x400, resultlength:0x26, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xE1, class:0x0, length:0x400, resultlength:0x2E, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xE2, class:0x0, length:0x400, resultlength:0x1E, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xE3, class:0x0, length:0x400, resultlength:0x26, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xE4, class:0x0, length:0x400, resultlength:0x2A, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"

pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind


ex:0xE5, class:0x0, length:0x400, resultlength:0x2A, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xE6, class:0x0, length:0x400, resultlength:0x26, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xE7, class:0x0, length:0x400, resultlength:0x1E, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xE8, class:0x0, length:0x400, resultlength:0x22, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xE9, class:0x0, length:0x400, resultlength:0x2C, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xEA, class:0x0, length:0x400, resultlength:0x32, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xEB, class:0x0, length:0x400, resultlength:0x2E, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xEC, class:0x0, length:0x400, resultlength:0x40, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xED, class:0x0, length:0x400, resultlength:0x26, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xEE, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xEF, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xF0, class:0x0, length:0x400, resultlength:0x38, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xF1, class:0x0, length:0x400, resultlength:0x46, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xF2, class:0x0, length:0x400, resultlength:0x46, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xF3, class:0x0, length:0x400, resultlength:0x46, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xF4, class:0x0, length:0x400, resultlength:0x46, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xF5, class:0x0, length:0x400, resultlength:0x46, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xF6, class:0x0, length:0x400, resultlength:0x46, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xF7, class:0x0, length:0x400, resultlength:0x46, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xF8, class:0x0, length:0x400, resultlength:0x46, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"

pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind


ex:0xF9, class:0x0, length:0x400, resultlength:0x4A, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xFA, class:0x0, length:0x400, resultlength:0x44, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xFB, class:0x0, length:0x400, resultlength:0x44, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xFC, class:0x0, length:0x400, resultlength:0x44, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xFD, class:0x0, length:0x400, resultlength:0x44, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xFE, class:0x0, length:0x400, resultlength:0x44, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0xFF, class:0x0, length:0x400, resultlength:0x44, handle:0x28, path:"\REGISTR
Y\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x100, class:0x0, length:0x400, resultlength:0x44, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x101, class:0x0, length:0x400, resultlength:0x44, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x102, class:0x0, length:0x400, resultlength:0x44, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x103, class:0x0, length:0x400, resultlength:0x44, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x104, class:0x0, length:0x400, resultlength:0x44, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x105, class:0x0, length:0x400, resultlength:0x44, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x106, class:0x0, length:0x400, resultlength:0x44, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x107, class:0x0, length:0x400, resultlength:0x44, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x108, class:0x0, length:0x400, resultlength:0x44, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x109, class:0x0, length:0x400, resultlength:0x44, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x10A, class:0x0, length:0x400, resultlength:0x44, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x10B, class:0x0, length:0x400, resultlength:0x44, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x10C, class:0x0, length:0x400, resultlength:0x44, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"

pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind


ex:0x10D, class:0x0, length:0x400, resultlength:0x44, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x10E, class:0x0, length:0x400, resultlength:0x44, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x10F, class:0x0, length:0x400, resultlength:0x44, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x110, class:0x0, length:0x400, resultlength:0x44, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x111, class:0x0, length:0x400, resultlength:0x44, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x112, class:0x0, length:0x400, resultlength:0x44, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x113, class:0x0, length:0x400, resultlength:0x46, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x114, class:0x0, length:0x400, resultlength:0x44, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x115, class:0x0, length:0x400, resultlength:0x44, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x116, class:0x0, length:0x400, resultlength:0x44, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x117, class:0x0, length:0x400, resultlength:0x44, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x118, class:0x0, length:0x400, resultlength:0x44, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x119, class:0x0, length:0x400, resultlength:0x44, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x11A, class:0x0, length:0x400, resultlength:0x44, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x11B, class:0x0, length:0x400, resultlength:0x44, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x11C, class:0x0, length:0x400, resultlength:0x44, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x11D, class:0x0, length:0x400, resultlength:0x44, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x11E, class:0x0, length:0x400, resultlength:0x44, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x11F, class:0x0, length:0x400, resultlength:0x44, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x120, class:0x0, length:0x400, resultlength:0x44, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"

pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind


ex:0x121, class:0x0, length:0x400, resultlength:0x44, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x122, class:0x0, length:0x400, resultlength:0x44, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x123, class:0x0, length:0x400, resultlength:0x44, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x124, class:0x0, length:0x400, resultlength:0x44, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x125, class:0x0, length:0x400, resultlength:0x44, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x126, class:0x0, length:0x400, resultlength:0x44, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x127, class:0x0, length:0x400, resultlength:0x44, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x128, class:0x0, length:0x400, resultlength:0x44, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x129, class:0x0, length:0x400, resultlength:0x44, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x12A, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x12B, class:0x0, length:0x400, resultlength:0x22, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x12C, class:0x0, length:0x400, resultlength:0x22, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x12D, class:0x0, length:0x400, resultlength:0x26, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x12E, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x12F, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x130, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x131, class:0x0, length:0x400, resultlength:0x3C, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x132, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x133, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x134, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"

pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind


ex:0x135, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x136, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x137, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x138, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x139, class:0x0, length:0x400, resultlength:0x22, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x13A, class:0x0, length:0x400, resultlength:0x40, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x13B, class:0x0, length:0x400, resultlength:0x40, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x13C, class:0x0, length:0x400, resultlength:0x20, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x13D, class:0x0, length:0x400, resultlength:0x2E, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x13E, class:0x0, length:0x400, resultlength:0x2A, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x13F, class:0x0, length:0x400, resultlength:0x2A, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x140, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x141, class:0x0, length:0x400, resultlength:0x26, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x142, class:0x0, length:0x400, resultlength:0x2A, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x143, class:0x0, length:0x400, resultlength:0x26, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x144, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x145, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x146, class:0x0, length:0x400, resultlength:0x22, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x147, class:0x0, length:0x400, resultlength:0x22, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x148, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"

pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind


ex:0x149, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x14A, class:0x0, length:0x400, resultlength:0x22, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x14B, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x14C, class:0x0, length:0x400, resultlength:0x1E, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x14D, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x14E, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x14F, class:0x0, length:0x400, resultlength:0x2E, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x150, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x151, class:0x0, length:0x400, resultlength:0x2C, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x152, class:0x0, length:0x400, resultlength:0x30, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x153, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x154, class:0x0, length:0x400, resultlength:0x20, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x155, class:0x0, length:0x400, resultlength:0x26, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x156, class:0x0, length:0x400, resultlength:0x34, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x157, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x158, class:0x0, length:0x400, resultlength:0x26, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x159, class:0x0, length:0x400, resultlength:0x34, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x15A, class:0x0, length:0x400, resultlength:0x26, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x15B, class:0x0, length:0x400, resultlength:0x32, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x15C, class:0x0, length:0x400, resultlength:0x26, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"

pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind


ex:0x15D, class:0x0, length:0x400, resultlength:0x1E, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x15E, class:0x0, length:0x400, resultlength:0x26, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x15F, class:0x0, length:0x400, resultlength:0x2C, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x160, class:0x0, length:0x400, resultlength:0x22, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x161, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x162, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x163, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x164, class:0x0, length:0x400, resultlength:0x2E, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x165, class:0x0, length:0x400, resultlength:0x3A, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x166, class:0x0, length:0x400, resultlength:0x2C, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x167, class:0x0, length:0x400, resultlength:0x2C, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x168, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x169, class:0x0, length:0x400, resultlength:0x2C, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x16A, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x16B, class:0x0, length:0x400, resultlength:0x20, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x16C, class:0x0, length:0x400, resultlength:0x2A, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x16D, class:0x0, length:0x400, resultlength:0x1E, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x16E, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x16F, class:0x0, length:0x400, resultlength:0x20, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x170, class:0x0, length:0x400, resultlength:0x20, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"

pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind


ex:0x171, class:0x0, length:0x400, resultlength:0x20, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x172, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x173, class:0x0, length:0x400, resultlength:0x38, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x174, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x175, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x176, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x177, class:0x0, length:0x400, resultlength:0x2E, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x178, class:0x0, length:0x400, resultlength:0x3C, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x179, class:0x0, length:0x400, resultlength:0x2E, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x17A, class:0x0, length:0x400, resultlength:0x22, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x17B, class:0x0, length:0x400, resultlength:0x40, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x17C, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x17D, class:0x0, length:0x400, resultlength:0x2C, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x17E, class:0x0, length:0x400, resultlength:0x3A, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x17F, class:0x0, length:0x400, resultlength:0x3A, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x180, class:0x0, length:0x400, resultlength:0x3A, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x181, class:0x0, length:0x400, resultlength:0x3A, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x182, class:0x0, length:0x400, resultlength:0x3A, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x183, class:0x0, length:0x400, resultlength:0x3A, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x184, class:0x0, length:0x400, resultlength:0x3A, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"

pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind


ex:0x185, class:0x0, length:0x400, resultlength:0x3A, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x186, class:0x0, length:0x400, resultlength:0x3E, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x187, class:0x0, length:0x400, resultlength:0x38, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x188, class:0x0, length:0x400, resultlength:0x38, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x189, class:0x0, length:0x400, resultlength:0x38, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x18A, class:0x0, length:0x400, resultlength:0x38, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x18B, class:0x0, length:0x400, resultlength:0x38, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x18C, class:0x0, length:0x400, resultlength:0x38, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x18D, class:0x0, length:0x400, resultlength:0x38, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x18E, class:0x0, length:0x400, resultlength:0x38, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x18F, class:0x0, length:0x400, resultlength:0x38, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x190, class:0x0, length:0x400, resultlength:0x38, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x191, class:0x0, length:0x400, resultlength:0x38, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x192, class:0x0, length:0x400, resultlength:0x38, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x193, class:0x0, length:0x400, resultlength:0x38, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x194, class:0x0, length:0x400, resultlength:0x38, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x195, class:0x0, length:0x400, resultlength:0x38, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x196, class:0x0, length:0x400, resultlength:0x38, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x197, class:0x0, length:0x400, resultlength:0x38, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x198, class:0x0, length:0x400, resultlength:0x38, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"

pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind


ex:0x199, class:0x0, length:0x400, resultlength:0x38, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x19A, class:0x0, length:0x400, resultlength:0x38, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x19B, class:0x0, length:0x400, resultlength:0x38, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x19C, class:0x0, length:0x400, resultlength:0x38, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x19D, class:0x0, length:0x400, resultlength:0x38, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x19E, class:0x0, length:0x400, resultlength:0x38, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x19F, class:0x0, length:0x400, resultlength:0x38, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1A0, class:0x0, length:0x400, resultlength:0x3A, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1A1, class:0x0, length:0x400, resultlength:0x38, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1A2, class:0x0, length:0x400, resultlength:0x38, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1A3, class:0x0, length:0x400, resultlength:0x38, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1A4, class:0x0, length:0x400, resultlength:0x38, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1A5, class:0x0, length:0x400, resultlength:0x38, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1A6, class:0x0, length:0x400, resultlength:0x38, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1A7, class:0x0, length:0x400, resultlength:0x38, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1A8, class:0x0, length:0x400, resultlength:0x38, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1A9, class:0x0, length:0x400, resultlength:0x38, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1AA, class:0x0, length:0x400, resultlength:0x38, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1AB, class:0x0, length:0x400, resultlength:0x38, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1AC, class:0x0, length:0x400, resultlength:0x38, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"

pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind


ex:0x1AD, class:0x0, length:0x400, resultlength:0x38, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1AE, class:0x0, length:0x400, resultlength:0x38, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1AF, class:0x0, length:0x400, resultlength:0x38, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1B0, class:0x0, length:0x400, resultlength:0x38, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1B1, class:0x0, length:0x400, resultlength:0x38, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1B2, class:0x0, length:0x400, resultlength:0x38, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1B3, class:0x0, length:0x400, resultlength:0x38, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1B4, class:0x0, length:0x400, resultlength:0x38, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1B5, class:0x0, length:0x400, resultlength:0x38, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1B6, class:0x0, length:0x400, resultlength:0x38, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1B7, class:0x0, length:0x400, resultlength:0x1E, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1B8, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1B9, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1BA, class:0x0, length:0x400, resultlength:0x26, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1BB, class:0x0, length:0x400, resultlength:0x26, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1BC, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1BD, class:0x0, length:0x400, resultlength:0x1E, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1BE, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1BF, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1C0, class:0x0, length:0x400, resultlength:0x1E, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"

pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind


ex:0x1C1, class:0x0, length:0x400, resultlength:0x1E, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1C2, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1C3, class:0x0, length:0x400, resultlength:0x2A, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1C4, class:0x0, length:0x400, resultlength:0x2A, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1C5, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1C6, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1C7, class:0x0, length:0x400, resultlength:0x26, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1C8, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1C9, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1CA, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1CB, class:0x0, length:0x400, resultlength:0x44, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1CC, class:0x0, length:0x400, resultlength:0x52, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1CD, class:0x0, length:0x400, resultlength:0x52, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1CE, class:0x0, length:0x400, resultlength:0x52, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1CF, class:0x0, length:0x400, resultlength:0x52, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1D0, class:0x0, length:0x400, resultlength:0x52, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1D1, class:0x0, length:0x400, resultlength:0x52, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1D2, class:0x0, length:0x400, resultlength:0x52, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1D3, class:0x0, length:0x400, resultlength:0x52, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1D4, class:0x0, length:0x400, resultlength:0x56, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"

pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind


ex:0x1D5, class:0x0, length:0x400, resultlength:0x50, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1D6, class:0x0, length:0x400, resultlength:0x50, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1D7, class:0x0, length:0x400, resultlength:0x50, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1D8, class:0x0, length:0x400, resultlength:0x50, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1D9, class:0x0, length:0x400, resultlength:0x50, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1DA, class:0x0, length:0x400, resultlength:0x50, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1DB, class:0x0, length:0x400, resultlength:0x50, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1DC, class:0x0, length:0x400, resultlength:0x50, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1DD, class:0x0, length:0x400, resultlength:0x50, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1DE, class:0x0, length:0x400, resultlength:0x50, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1DF, class:0x0, length:0x400, resultlength:0x50, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1E0, class:0x0, length:0x400, resultlength:0x50, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1E1, class:0x0, length:0x400, resultlength:0x50, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1E2, class:0x0, length:0x400, resultlength:0x50, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1E3, class:0x0, length:0x400, resultlength:0x50, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1E4, class:0x0, length:0x400, resultlength:0x50, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1E5, class:0x0, length:0x400, resultlength:0x50, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1E6, class:0x0, length:0x400, resultlength:0x50, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1E7, class:0x0, length:0x400, resultlength:0x50, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1E8, class:0x0, length:0x400, resultlength:0x50, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"

pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind


ex:0x1E9, class:0x0, length:0x400, resultlength:0x50, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1EA, class:0x0, length:0x400, resultlength:0x50, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1EB, class:0x0, length:0x400, resultlength:0x50, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1EC, class:0x0, length:0x400, resultlength:0x50, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1ED, class:0x0, length:0x400, resultlength:0x50, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1EE, class:0x0, length:0x400, resultlength:0x52, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1EF, class:0x0, length:0x400, resultlength:0x50, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1F0, class:0x0, length:0x400, resultlength:0x50, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1F1, class:0x0, length:0x400, resultlength:0x50, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1F2, class:0x0, length:0x400, resultlength:0x50, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1F3, class:0x0, length:0x400, resultlength:0x50, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1F4, class:0x0, length:0x400, resultlength:0x50, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1F5, class:0x0, length:0x400, resultlength:0x50, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1F6, class:0x0, length:0x400, resultlength:0x50, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1F7, class:0x0, length:0x400, resultlength:0x50, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1F8, class:0x0, length:0x400, resultlength:0x50, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1F9, class:0x0, length:0x400, resultlength:0x50, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1FA, class:0x0, length:0x400, resultlength:0x50, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1FB, class:0x0, length:0x400, resultlength:0x50, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1FC, class:0x0, length:0x400, resultlength:0x50, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"

pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind


ex:0x1FD, class:0x0, length:0x400, resultlength:0x50, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1FE, class:0x0, length:0x400, resultlength:0x50, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1FF, class:0x0, length:0x400, resultlength:0x50, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x200, class:0x0, length:0x400, resultlength:0x50, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x201, class:0x0, length:0x400, resultlength:0x50, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x202, class:0x0, length:0x400, resultlength:0x50, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x203, class:0x0, length:0x400, resultlength:0x50, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x204, class:0x0, length:0x400, resultlength:0x50, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x205, class:0x0, length:0x400, resultlength:0x1E, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x206, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x207, class:0x0, length:0x400, resultlength:0x2E, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x208, class:0x0, length:0x400, resultlength:0x26, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x209, class:0x0, length:0x400, resultlength:0x2E, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x20A, class:0x0, length:0x400, resultlength:0x2A, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x20B, class:0x0, length:0x400, resultlength:0x22, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x20C, class:0x0, length:0x400, resultlength:0x30, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x20D, class:0x0, length:0x400, resultlength:0x2E, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x20E, class:0x0, length:0x400, resultlength:0x2A, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x20F, class:0x0, length:0x400, resultlength:0x26, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x210, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"

pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind


ex:0x211, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x212, class:0x0, length:0x400, resultlength:0x22, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x213, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x214, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x215, class:0x0, length:0x400, resultlength:0x2E, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x216, class:0x0, length:0x400, resultlength:0x26, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x217, class:0x0, length:0x400, resultlength:0x26, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x218, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x219, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x21A, class:0x0, length:0x400, resultlength:0x26, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x21B, class:0x0, length:0x400, resultlength:0x22, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x21C, class:0x0, length:0x400, resultlength:0x26, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x21D, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x21E, class:0x0, length:0x400, resultlength:0x22, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x21F, class:0x0, length:0x400, resultlength:0x22, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x220, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x221, class:0x0, length:0x400, resultlength:0x38, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x222, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x223, class:0x0, length:0x400, resultlength:0x40, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x224, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"

pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind


ex:0x225, class:0x0, length:0x400, resultlength:0x30, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x226, class:0x0, length:0x400, resultlength:0x34, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x227, class:0x0, length:0x400, resultlength:0x2C, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x228, class:0x0, length:0x400, resultlength:0x30, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x229, class:0x0, length:0x400, resultlength:0x2C, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x22A, class:0x0, length:0x400, resultlength:0x22, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x22B, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x22C, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x22D, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x22E, class:0x0, length:0x400, resultlength:0x22, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x22F, class:0x0, length:0x400, resultlength:0x22, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x230, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x231, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x232, class:0x0, length:0x400, resultlength:0x30, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x233, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x234, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x235, class:0x0, length:0x400, resultlength:0x2E, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x236, class:0x0, length:0x400, resultlength:0x22, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x237, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x238, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"

pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind


ex:0x239, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x23A, class:0x0, length:0x400, resultlength:0x20, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x23B, class:0x0, length:0x400, resultlength:0x3A, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x23C, class:0x0, length:0x400, resultlength:0x32, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x23D, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x23E, class:0x0, length:0x400, resultlength:0x22, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x23F, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x240, class:0x0, length:0x400, resultlength:0x26, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x241, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x242, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x243, class:0x0, length:0x400, resultlength:0x50, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x244, class:0x0, length:0x400, resultlength:0x52, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x245, class:0x0, length:0x400, resultlength:0x4E, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x246, class:0x0, length:0x400, resultlength:0x2C, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x247, class:0x0, length:0x400, resultlength:0x26, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x248, class:0x0, length:0x400, resultlength:0x38, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x249, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x24A, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x24B, class:0x0, length:0x400, resultlength:0x2E, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x24C, class:0x0, length:0x400, resultlength:0x26, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"

pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind


ex:0x24D, class:0x0, length:0x400, resultlength:0x2A, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x24E, class:0x0, length:0x400, resultlength:0x3A, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x24F, class:0x0, length:0x400, resultlength:0x3A, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x250, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x251, class:0x0, length:0x400, resultlength:0x3A, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x252, class:0x0, length:0x400, resultlength:0x2A, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x253, class:0x0, length:0x400, resultlength:0x22, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x254, class:0x0, length:0x400, resultlength:0x26, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x255, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x256, class:0x0, length:0x400, resultlength:0x1E, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x257, class:0x0, length:0x400, resultlength:0x20, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x258, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x259, class:0x0, length:0x400, resultlength:0x26, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x25A, class:0x0, length:0x400, resultlength:0x26, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x25B, class:0x0, length:0x400, resultlength:0x26, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x25C, class:0x0, length:0x400, resultlength:0x36, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x25D, class:0x0, length:0x400, resultlength:0x36, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x25E, class:0x0, length:0x400, resultlength:0x40, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x25F, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x260, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"

pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind


ex:0x261, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x262, class:0x0, length:0x400, resultlength:0x26, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x263, class:0x0, length:0x400, resultlength:0x28, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x264, class:0x0, length:0x400, resultlength:0x2C, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x265, class:0x0, length:0x400, resultlength:0x26, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x266, class:0x0, length:0x400, resultlength:0x26, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x267, class:0x0, length:0x400, resultlength:0x26, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x268, class:0x0, length:0x400, resultlength:0x22, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x269, class:0x0, length:0x400, resultlength:0x24, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x26A, class:0x0, length:0x400, resultlength:0x2E, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x26B, class:0x0, length:0x400, resultlength:0x22, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x26C, class:0x0, length:0x400, resultlength:0x2C, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x26D, class:0x0, length:0x400, resultlength:0x26, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x26E, class:0x0, length:0x400, resultlength:0x3C, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x26F, class:0x0, length:0x400, resultlength:0x3C, handle:0x28, path:"\REGIST
RY\MACHINE\System\CurrentControlSet\Services"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"kernel32", module:0x74CD0000
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"kernel32", module:0x74CD0000
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"kernel32", module:0x74CD0000
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"kernel32", module:0x74CD0000
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"kernel32", module:0x74CD0000
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtOpenSection, status:0x0, hand
le:0xE4, access:0xF, path:"\KnownDlls32\psapi.dll"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x74DB0000, zerobits:0x0, commitsize:0x0, viewsize:0x6000, disposition:
0x1, type:0x800000, protect:0x4, handle:0xE4, path:"\KnownDlls32\PSAPI.DLL"

pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtClose, status:0x0, handle:0xE


4
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"psapi.dll", handle:0x74DB0000
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"psapi", module:0x74DB0000
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"advapi32", module:0x77B40000
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"advapi32", module:0x77B40000
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"advapi32", module:0x77B40000
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"advapi32", module:0x77B40000
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"advapi32", module:0x77B40000
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"advapi32", module:0x77B40000
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"advapi32", module:0x77B40000
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"advapi32", module:0x77B40000
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"advapi32", module:0x77B40000
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"advapi32", module:0x77B40000
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"advapi32", module:0x77B40000
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"advapi32", module:0x77B40000
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"advapi32", module:0x77B40000
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"advapi32", module:0x77B40000
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"advapi32", module:0x77B40000
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"advapi32", module:0x77B40000
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"advapi32", module:0x77B40000
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"advapi32", module:0x77B40000
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"advapi32", module:0x77B40000
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"advapi32", module:0x77B40000
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"advapi32", module:0x77B40000
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"advapi32", module:0x77B40000
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtOpenSection, status:0x0, hand
le:0xE4, access:0xF, path:"\KnownDlls32\shell32.dll"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x75670000, zerobits:0x0, commitsize:0x0, viewsize:0x13FE000, dispositi
on:0x1, type:0x800000, protect:0x4, handle:0xE4, path:"\KnownDlls32\SHELL32.dll"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtOpenSection, status:0x0, hand
le:0x1D4, access:0xF, path:"\KnownDlls32\cfgmgr32.dll"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x75210000, zerobits:0x0, commitsize:0x0, viewsize:0x37000, disposition
:0x1, type:0x800000, protect:0x4, handle:0x1D4, path:"\KnownDlls32\CFGMGR32.dll"

pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtClose, status:0x0, handle:0x1


D4
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtOpenSection, status:0x0, hand
le:0x1D4, access:0xF, path:"\KnownDlls32\windows.storage.dll"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x76B00000, zerobits:0x0, commitsize:0x0, viewsize:0x4FA000, dispositio
n:0x1, type:0x800000, protect:0x4, handle:0x1D4, path:"\KnownDlls32\windows.stor
age.dll"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtOpenSection, status:0x0, hand
le:0x1D8, access:0xF, path:"\KnownDlls32\combase.dll"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x74DC0000, zerobits:0x0, commitsize:0x0, viewsize:0x1BD000, dispositio
n:0x1, type:0x800000, protect:0x4, handle:0x1D8, path:"\KnownDlls32\combase.dll"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtClose, status:0x0, handle:0x1
D8
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtOpenSection, status:0x0, hand
le:0x1D8, access:0xF, path:"\KnownDlls32\shlwapi.dll"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x77BC0000, zerobits:0x0, commitsize:0x0, viewsize:0x45000, disposition
:0x1, type:0x800000, protect:0x4, handle:0x1D8, path:"\KnownDlls32\SHLWAPI.dll"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtOpenSection, status:0x0, hand
le:0x1DC, access:0xF, path:"\KnownDlls32\GDI32.dll"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x779F0000, zerobits:0x0, commitsize:0x0, viewsize:0x14F000, dispositio
n:0x1, type:0x800000, protect:0x4, handle:0x1DC, path:"\KnownDlls32\gdi32.dll"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtOpenSection, status:0x0, hand
le:0x1E0, access:0xF, path:"\KnownDlls32\USER32.dll"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x75050000, zerobits:0x0, commitsize:0x0, viewsize:0x147000, dispositio
n:0x1, type:0x800000, protect:0x4, handle:0x1E0, path:"\KnownDlls32\user32.dll"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtClose, status:0x0, handle:0x1
E0
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtClose, status:0x0, handle:0x1
DC
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtClose, status:0x0, handle:0x1
D8
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtOpenSection, status:0x0, hand
le:0x1D8, access:0xF, path:"\KnownDlls32\kernel.appcore.dll"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x74B10000, zerobits:0x0, commitsize:0x0, viewsize:0xC000, disposition:
0x1, type:0x800000, protect:0x4, handle:0x1D8, path:"\KnownDlls32\kernel.appcore
.dll"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtClose, status:0x0, handle:0x1
D8
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtOpenSection, status:0x0, hand
le:0x1D8, access:0xF, path:"\KnownDlls32\shcore.dll"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x74B20000, zerobits:0x0, commitsize:0x0, viewsize:0x8D000, disposition
:0x1, type:0x800000, protect:0x4, handle:0x1D8, path:"\KnownDlls32\shcore.dll"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtClose, status:0x0, handle:0x1
D8
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtOpenSection, status:0x0, hand
le:0x1D8, access:0xF, path:"\KnownDlls32\powrprof.dll"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x74FE0000, zerobits:0x0, commitsize:0x0, viewsize:0x44000, disposition
:0x1, type:0x800000, protect:0x4, handle:0x1D8, path:"\KnownDlls32\powrprof.dll"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtClose, status:0x0, handle:0x1
D8
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtOpenSection, status:0x0, hand
le:0x1D8, access:0xF, path:"\KnownDlls32\profapi.dll"

pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtMapViewOfSection, status:0x0,


address:0x75430000, zerobits:0x0, commitsize:0x0, viewsize:0xF000, disposition:
0x1, type:0x800000, protect:0x4, handle:0x1D8, path:"\KnownDlls32\profapi.dll"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtClose, status:0x0, handle:0x1
D8
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtClose, status:0x0, handle:0x1
D4
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtSetInformationProcess, status
:0x0, class:0x23, length:0x1C
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtClose, status:0x0, handle:0xE
4
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtSetInformationProcess, status
:0x0, class:0x23, length:0x1C
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtSetInformationProcess, status
:0x0, class:0x23, length:0x1C
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtCreateFile, status:0x0, handl
e:0xE4, access:0x80000000, iostatus:0x0, information:0x0, attribs:0x0, share:0x0
, disposition:0x1, options:0x0, path:"\Device\DeviceApi\CMApi"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x580000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x570000
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x570000, zerobits:0x0, commitsize:0x0, offset:0x220000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x580000
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x580000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x570000
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x1D4, access:0x2000000, path:"\REGISTRY\MACHINE"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x570000, zerobits:0x0, commitsize:0x0, offset:0x220000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x580000
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x1D8, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\Microsoft\OLE"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"PageAllocatorUseSystemHeap", class:0x2, length:0x90, resultlength:0x
0, handle:0x1D8, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\OLE"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtClose, status:0x0, handle:0x1
D8
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x1D8, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\Microsoft\OLE"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"PageAllocatorSystemHeapIsPrivate", class:0x2, length:0x90, resultlen
gth:0x0, handle:0x1D8, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\OLE"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtClose, status:0x0, handle:0x1
D8
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x1D8, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\Microsoft\OLE"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"AggressiveMTATesting", class:0x2, length:0x90, resultlength:0x0, han
dle:0x1D8, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\OLE"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtClose, status:0x0, handle:0x1

D8
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"rpcrt4.dll", module:0x77000000
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77000000, name:"I_RpcInitNdrImports", ordinal:0x0, addres
s:0x77036110, image:0x0, caller:0x74E980E2
pid:4092, tid:2168, tick:0x33D6FB1, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\OLE\Tra
cing"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:LOG, func:NtOpenEvent, status:0xC0000034
, handle:0x0, access:0x100000, path:"\Sessions\1\BaseNamedObjects\HookSwitchHook
EnabledEvent"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x20, path:"C:\WINDOWS\system32\IMM32.DLL"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtOpenFile, status:0x0, handle:
0x208, access:0x100001, iostatus:0x0, information:0x1, share:0x5, options:0x60,
path:"C:\WINDOWS\system32\IMM32.DLL"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtCreateSection, status:0x0, ha
ndle:0x20C, access:0x4, pageattribs:0x2, sectionattribs:0x8000000, file:0x208
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x580000, zerobits:0x0, commitsize:0x0, viewsize:0x2A000, disposition:0
x1, type:0x0, protect:0x2, handle:0x20C, path:"C:\WINDOWS\system32\IMM32.DLL"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x580000
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtClose, status:0x0, handle:0x2
0C
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtClose, status:0x0, handle:0x2
08
pid:4092, tid:2168, tick:0x33D6FB1, lvl:LOG, func:LdrGetDllHandle, status:0xC000
0135, name:"C:\WINDOWS\system32\IMM32.DLL"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtOpenSection, status:0x0, hand
le:0x208, access:0xF, path:"\KnownDlls32\IMM32.DLL"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x77670000, zerobits:0x0, commitsize:0x0, viewsize:0x2B000, disposition
:0x1, type:0x800000, protect:0x4, handle:0x208, path:"\KnownDlls32\IMM32.dll"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtClose, status:0x0, handle:0x2
08
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x20, path:"C:\WINDOWS\system32\IMM32.DLL"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"C:\WINDOWS\system32\IMM32.DLL", module:0x77670000
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"ImmWINNLSEnableIME", ordinal:0x0, address
:0x77688860, image:0x0, caller:0x750628CF
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"ImmWINNLSGetEnableStatus", ordinal:0x0, a
ddress:0x77688890, image:0x0, caller:0x750628E8
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"ImmSendIMEMessageExW", ordinal:0x0, addre
ss:0x77688840, image:0x0, caller:0x75062901
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"ImmSendIMEMessageExA", ordinal:0x0, addre
ss:0x77688820, image:0x0, caller:0x7506291A
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"ImmIMPGetIMEW", ordinal:0x0, address:0x77
688490, image:0x0, caller:0x75062933
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"ImmIMPGetIMEA", ordinal:0x0, address:0x77
688420, image:0x0, caller:0x7506294C
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetProcedureAddressForCaller

, status:0x0, module:0x77670000, name:"ImmIMPQueryIMEW", ordinal:0x0, address:0x


77688570, image:0x0, caller:0x75062965
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"ImmIMPQueryIMEA", ordinal:0x0, address:0x
776884D0, image:0x0, caller:0x7506297E
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"ImmIMPSetIMEW", ordinal:0x0, address:0x77
688710, image:0x0, caller:0x75062997
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"ImmIMPSetIMEA", ordinal:0x0, address:0x77
688690, image:0x0, caller:0x750629B0
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"ImmAssociateContext", ordinal:0x0, addres
s:0x77672380, image:0x0, caller:0x750629C9
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"ImmEscapeA", ordinal:0x0, address:0x77681
640, image:0x0, caller:0x750629E2
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"ImmEscapeW", ordinal:0x0, address:0x77681
900, image:0x0, caller:0x750629FB
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"ImmGetCompositionStringA", ordinal:0x0, a
ddress:0x7767E280, image:0x0, caller:0x75062A14
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"ImmGetCompositionStringW", ordinal:0x0, a
ddress:0x7767E320, image:0x0, caller:0x75062A2D
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"ImmGetCompositionWindow", ordinal:0x0, ad
dress:0x776728A0, image:0x0, caller:0x75062A46
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"ImmGetContext", ordinal:0x0, address:0x77
672D10, image:0x0, caller:0x75062A5F
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"ImmGetDefaultIMEWnd", ordinal:0x0, addres
s:0x77675000, image:0x0, caller:0x75062A78
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"ImmIsIME", ordinal:0x0, address:0x7767505
0, image:0x0, caller:0x75062A91
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"ImmReleaseContext", ordinal:0x0, address:
0x77675430, image:0x0, caller:0x75062AAA
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"ImmRegisterClient", ordinal:0x0, address:
0x776760E0, image:0x0, caller:0x75062AC3
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"ImmGetCompositionFontW", ordinal:0x0, add
ress:0x7767E1D0, image:0x0, caller:0x75062ADC
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"ImmGetCompositionFontA", ordinal:0x0, add
ress:0x7767E120, image:0x0, caller:0x75062AF5
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"ImmSetCompositionFontW", ordinal:0x0, add
ress:0x77672210, image:0x0, caller:0x75062B0E
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"ImmSetCompositionFontA", ordinal:0x0, add
ress:0x7767EF70, image:0x0, caller:0x75062B27
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"ImmSetCompositionWindow", ordinal:0x0, ad
dress:0x77673780, image:0x0, caller:0x75062B40
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetProcedureAddressForCaller

, status:0x0, module:0x77670000, name:"ImmNotifyIME", ordinal:0x0, address:0x776


81CB0, image:0x0, caller:0x75062B59
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"ImmLockIMC", ordinal:0x0, address:0x77672
DE0, image:0x0, caller:0x75062B72
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"ImmUnlockIMC", ordinal:0x0, address:0x776
73F00, image:0x0, caller:0x75062B8B
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"ImmLoadIME", ordinal:0x0, address:0x77675
DF0, image:0x0, caller:0x75062BA4
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"ImmSetOpenStatus", ordinal:0x0, address:0
x7767F660, image:0x0, caller:0x75062BBD
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"ImmFreeLayout", ordinal:0x0, address:0x77
681B10, image:0x0, caller:0x75062BD6
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"ImmActivateLayout", ordinal:0x0, address:
0x77681060, image:0x0, caller:0x75062BEF
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"ImmGetCandidateWindow", ordinal:0x0, addr
ess:0x77672B40, image:0x0, caller:0x75062C08
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"ImmSetCandidateWindow", ordinal:0x0, addr
ess:0x7767EEE0, image:0x0, caller:0x75062C21
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"ImmConfigureIMEW", ordinal:0x0, address:0
x77681400, image:0x0, caller:0x75062C3A
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"ImmGetConversionStatus", ordinal:0x0, add
ress:0x77672750, image:0x0, caller:0x75062C53
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"ImmSetConversionStatus", ordinal:0x0, add
ress:0x7767F580, image:0x0, caller:0x75062C6C
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"ImmSetStatusWindowPos", ordinal:0x0, addr
ess:0x7767F700, image:0x0, caller:0x75062C85
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"ImmGetImeInfoEx", ordinal:0x0, address:0x
77675F00, image:0x0, caller:0x75062C9E
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"ImmLockImeDpi", ordinal:0x0, address:0x77
673E70, image:0x0, caller:0x75062CB7
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"ImmUnlockImeDpi", ordinal:0x0, address:0x
77672700, image:0x0, caller:0x75062CD0
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"ImmGetOpenStatus", ordinal:0x0, address:0
x776727F0, image:0x0, caller:0x75062CE9
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"ImmSetActiveContext", ordinal:0x0, addres
s:0x776733B0, image:0x0, caller:0x75062D02
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"ImmTranslateMessage", ordinal:0x0, addres
s:0x77687F00, image:0x0, caller:0x75062D1B
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"ImmLoadLayout", ordinal:0x0, address:0x77
682160, image:0x0, caller:0x75062D34
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetProcedureAddressForCaller

, status:0x0, module:0x77670000, name:"ImmProcessKey", ordinal:0x0, address:0x77


6742D0, image:0x0, caller:0x75062D4D
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"ImmPutImeMenuItemsIntoMappedFile", ordina
l:0x0, address:0x7768D9E0, image:0x0, caller:0x75062D66
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"ImmGetProperty", ordinal:0x0, address:0x7
7682FE0, image:0x0, caller:0x75062D7F
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"ImmSetCompositionStringA", ordinal:0x0, a
ddress:0x7767F0A0, image:0x0, caller:0x75062D98
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"ImmSetCompositionStringW", ordinal:0x0, a
ddress:0x7767F0D0, image:0x0, caller:0x75062DB1
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"ImmEnumInputContext", ordinal:0x0, addres
s:0x776740B0, image:0x0, caller:0x75062DCA
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"ImmSystemHandler", ordinal:0x0, address:0
x77683D90, image:0x0, caller:0x75062DE3
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"CtfImmTIMActivate", ordinal:0x0, address:
0x77675F80, image:0x0, caller:0x75062DFC
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"CtfImmRestoreToolbarWnd", ordinal:0x0, ad
dress:0x7768E0D0, image:0x0, caller:0x75062E15
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"CtfImmHideToolbarWnd", ordinal:0x0, addre
ss:0x7768DF60, image:0x0, caller:0x75062E2A
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"CtfImmDispatchDefImeMessage", ordinal:0x0
, address:0x77675AA0, image:0x0, caller:0x75062E3F
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"CtfImmNotify", ordinal:0x0, address:0x776
75AE0, image:0x0, caller:0x75062E54
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"CtfImmSetDefaultRemoteKeyboardLayout", or
dinal:0x0, address:0x7768E140, image:0x0, caller:0x75062E69
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"CtfImmGetCompatibleKeyboardLayout", ordin
al:0x0, address:0x7768DE00, image:0x0, caller:0x75062E7E
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"C:\WINDOWS\system32\IMM32.DLL", handle:0x77670000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x20, path:"C:\WINDOWS\system32\IMM32.DLL"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"C:\WINDOWS\system32\IMM32.DLL", module:0x77670000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x208, access:0x20019, path:"\Registry\Machine\Software\Microsoft\Windows NT\Curr
entVersion\GRE_Initialize"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DisableMetaFiles", class:0x2, length:0x14, resultlength:0x680000, ha
ndle:0x208, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION
\GRE_Initialize"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtClose, status:0x0, handle:0x2
08
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x218, access:0x1, path:"\Registry\MACHINE\SYSTEM\CurrentControlSet\Control\Nls\C
ustomLocale"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:LOG, func:NtQueryValueKey, status:0xC000

0034, name:"EMPTY", class:0x2, length:0x78, resultlength:0x768FB0, handle:0x218,


path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"EMPTY", class:0x2, length:0x78, resultlength:0x768FB0, handle:0x218,
path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x21C, access:0x20019, path:"\Registry\Machine\System\CurrentControlSet\Control\N
LS\Language"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:LOG, func:NtQueryValueKey, status:0x8000
0005, name:"InstallLanguageFallback", class:0x2, length:0x10, resultlength:0x1A,
handle:0x21C, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Nls\Language
"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtClose, status:0x0, handle:0x2
1C
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x21C, access:0x20019, path:"\Registry\Machine\System\CurrentControlSet\Control\M
UI\UILanguages"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x0, class:0x0, length:0x200, resultlength:0x1A, handle:0x21C, path:"\REGISTR
Y\MACHINE\SYSTEM\ControlSet001\Control\MUI\UILanguages"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x220, access:0x20019, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\MUI\U
ILanguages\es-ES"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Type", class:0x2, length:0x10, resultlength:0x10, handle:0x220, path:"\REGIS
TRY\MACHINE\SYSTEM\ControlSet001\Control\MUI\UILanguages\es-ES"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"DefaultFallback", class:0x2, length:0xB6, resultlength:0x18, handle:0x220, p
ath:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\MUI\UILanguages\es-ES"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"en-US", class:0x1, length:0x200, resultlength:0x24, handle:0x220, path:"\REG
ISTRY\MACHINE\SYSTEM\ControlSet001\Control\MUI\UILanguages\es-ES"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtEnumerateValueKey, status:0x0
, index:0x0, class:0x1, length:0x200, resultlength:0x44, handle:0x220, path:"\RE
GISTRY\MACHINE\SYSTEM\ControlSet001\Control\MUI\UILanguages\es-ES"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtEnumerateValueKey, status:0x0
, index:0x1, class:0x1, length:0x200, resultlength:0x24, handle:0x220, path:"\RE
GISTRY\MACHINE\SYSTEM\ControlSet001\Control\MUI\UILanguages\es-ES"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtEnumerateValueKey, status:0x0
, index:0x2, class:0x1, length:0x200, resultlength:0x24, handle:0x220, path:"\RE
GISTRY\MACHINE\SYSTEM\ControlSet001\Control\MUI\UILanguages\es-ES"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtEnumerateValueKey, status:0x0
, index:0x3, class:0x1, length:0x200, resultlength:0x24, handle:0x220, path:"\RE
GISTRY\MACHINE\SYSTEM\ControlSet001\Control\MUI\UILanguages\es-ES"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:LOG, func:NtEnumerateValueKey, status:0x
8000001A, index:0x4, class:0x1, length:0x200, resultlength:0x24, handle:0x220, p
ath:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\MUI\UILanguages\es-ES"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"AlternateCodePage", class:0x2, length:0xC, resultlength:0x0, handle:
0x220, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\MUI\UILanguages\es-E
S"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtClose, status:0x0, handle:0x2
20
pid:4092, tid:2168, tick:0x33D6FC1, lvl:LOG, func:NtEnumerateKey, status:0x80000
01A, index:0x1, class:0x0, length:0x200, resultlength:0x1A, handle:0x21C, path:"
\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\MUI\UILanguages"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtClose, status:0x0, handle:0x2
1C
pid:4092, tid:2168, tick:0x33D6FC1, lvl:LOG, func:NtOpenKey, status:0xC0000034,
handle:0x0, access:0x20019, path:"\Registry\Machine\System\CurrentControlSet\Con

trol\MUI\UILanguages\PendingDelete"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:LOG, func:NtOpenKey, status:0xC0000034,
handle:0x0, access:0x20019, path:"\Registry\Machine\Software\Policies\Microsoft\
MUI\Settings"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x580000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x570000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x570000, zerobits:0x0, commitsize:0x0, offset:0x210000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x580000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x580000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x570000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x220, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:LOG, func:NtOpenKey, status:0xC0000034,
handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-26023833972463990887-1001\Control Panel\Desktop\MuiCached\MachineLanguageConfiguration"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x224, access:0x20019, path:"\Registry\Machine\System\CurrentControlSet\Control\M
UI\Settings\LanguageConfiguration"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:LOG, func:NtEnumerateValueKey, status:0x
8000001A, index:0x0, class:0x1, length:0x200, resultlength:0x2000B09, handle:0x2
24, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\MUI\Settings\LanguageCo
nfiguration"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtClose, status:0x0, handle:0x2
24
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtClose, status:0x0, handle:0x2
20
pid:4092, tid:2168, tick:0x33D6FC1, lvl:LOG, func:NtOpenKey, status:0xC0000034,
handle:0x0, access:0x20019, path:"\Registry\Machine\Software\Policies\Microsoft\
MUI\Settings"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x220, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x570000, zerobits:0x0, commitsize:0x0, offset:0x210000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x580000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x580000, zerobits:0x0, commitsize:0x0, offset:0x220000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x570000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x570000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x580000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:LOG, func:RecurseRegistryConfig, log:"Du
plicate regkey Classes will not be added as it is at lower layer."
pid:4092, tid:2168, tick:0x33D6FC1, lvl:LOG, func:RecurseRegistryConfig, log:"Du

plicate regkey Microsoft will not be added as it is at lower layer."


pid:4092, tid:2168, tick:0x33D6FC1, lvl:LOG, func:NtOpenKey, status:0xC0000034,
handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-26023833972463990887-1001\Software\Policies\Microsoft\Control Panel\Desktop"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x224, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246399
0887-1001\Control Panel\Desktop\LanguageConfiguration"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:LOG, func:NtEnumerateValueKey, status:0x
8000001A, index:0x0, class:0x1, length:0x200, resultlength:0x2000002, handle:0x2
24, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\Control
Panel\Desktop\LanguageConfiguration"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtClose, status:0x0, handle:0x2
24
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtClose, status:0x0, handle:0x2
20
pid:4092, tid:2168, tick:0x33D6FC1, lvl:LOG, func:NtOpenKey, status:0xC0000034,
handle:0x0, access:0x20019, path:"\Registry\Machine\Software\Policies\Microsoft\
MUI\Settings"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x220, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:LOG, func:NtOpenKey, status:0xC0000034,
handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-26023833972463990887-1001\Software\Policies\Microsoft\Control Panel\Desktop"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x224, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246399
0887-1001\Control Panel\Desktop"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"PreferredUILanguages", class:0x2, length:0xC, resultlength:0x0, hand
le:0x224, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\Co
ntrol Panel\Desktop"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtClose, status:0x0, handle:0x2
24
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtClose, status:0x0, handle:0x2
20
pid:4092, tid:2168, tick:0x33D6FC1, lvl:LOG, func:NtOpenKey, status:0xC0000034,
handle:0x0, access:0x20019, path:"\Registry\Machine\Software\Policies\Microsoft\
MUI\Settings"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x220, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x224, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246399
0887-1001\Control Panel\Desktop\MuiCached"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:LOG, func:NtQueryValueKey, status:0x8000
0005, name:"MachinePreferredUILanguages", class:0x2, length:0xC, resultlength:0x
18, handle:0x224, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887
-1001\Control Panel\Desktop\MuiCached"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"MachinePreferredUILanguages", class:0x2, length:0x18, resultlength:0x18, han
dle:0x224, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\C
ontrol Panel\Desktop\MuiCached"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtClose, status:0x0, handle:0x2
24
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtClose, status:0x0, handle:0x2
20
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtCreateSemaphore, status:0x0,
handle:0x264, access:0x100003, initialcount:0x0, maxcount:0x7FFFFFFF
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtCreateSemaphore, status:0x0,
handle:0x268, access:0x100003, initialcount:0x0, maxcount:0x7FFFFFFF

pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na


me:"advapi32.dll", module:0x77B40000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77B40000, name:"EventWrite", ordinal:0x0, address:0x77C6D
C10, image:0x0, caller:0x757C11C3
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77B40000, name:"EventRegister", ordinal:0x0, address:0x77
C3B590, image:0x0, caller:0x757C11DC
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77B40000, name:"EventUnregister", ordinal:0x0, address:0x
77C41E30, image:0x0, caller:0x757C11F5
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"ntdll.dll", module:0x77C10000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77C10000, name:"EtwEventRegister", ordinal:0x0, address:0
x77C3B590, image:0x0, caller:0x7582E069
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77C10000, name:"EtwEventUnregister", ordinal:0x0, address
:0x77C41E30, image:0x0, caller:0x7582E07C
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77C10000, name:"EtwEventEnabled", ordinal:0x0, address:0x
77C6FE90, image:0x0, caller:0x7582E08F
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77C10000, name:"EtwEventWrite", ordinal:0x0, address:0x77
C6DC10, image:0x0, caller:0x7582E0A2
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"shell32.dll", handle:0x75670000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"shell32", module:0x75670000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"shell32", module:0x75670000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtOpenSection, status:0x0, hand
le:0x298, access:0xF, path:"\KnownDlls32\ole32.dll"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x75580000, zerobits:0x0, commitsize:0x0, viewsize:0xEB000, disposition
:0x1, type:0x800000, protect:0x4, handle:0x298, path:"\KnownDlls32\ole32.dll"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtClose, status:0x0, handle:0x2
98
pid:4092, tid:2168, tick:0x33D6FC1, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\OLE\Tra
cing"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x20, path:"C:\WINDOWS\system32\oleaut32.dll"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtOpenFile, status:0x0, handle:
0x2A0, access:0x100001, iostatus:0x0, information:0x1, share:0x5, options:0x60,
path:"C:\WINDOWS\system32\oleaut32.dll"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtCreateSection, status:0x0, ha
ndle:0x2A4, access:0x4, pageattribs:0x2, sectionattribs:0x8000000, file:0x2A0
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0xD90000, zerobits:0x0, commitsize:0x0, viewsize:0x93000, disposition:0
x1, type:0x0, protect:0x2, handle:0x2A4, path:"C:\WINDOWS\system32\oleaut32.dll"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0xD90000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtClose, status:0x0, handle:0x2
A4
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtClose, status:0x0, handle:0x2
A0
pid:4092, tid:2168, tick:0x33D6FC1, lvl:LOG, func:LdrGetDllHandle, status:0xC000
0135, name:"C:\WINDOWS\system32\oleaut32.dll"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrLoadDll, status:0x0, flags:0

x0, module:"ole32.dll", handle:0x75580000


pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"ole32", module:0x75580000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"ole32", module:0x75580000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtOpenSection, status:0x0, hand
le:0x2A4, access:0xF, path:"\KnownDlls32\oleaut32.dll"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x754E0000, zerobits:0x0, commitsize:0x0, viewsize:0x95000, disposition
:0x1, type:0x800000, protect:0x4, handle:0x2A4, path:"\KnownDlls32\OLEAUT32.dll"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtClose, status:0x0, handle:0x2
A4
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x20, path:"C:\WINDOWS\SYSTEM32\ole32.dll"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"ext-ms-win-ole32-oleautomation-l1-1-0.dll", module:0x75580000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x754E0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\Microsoft\OLEAUT"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"oleaut32.dll", handle:0x754E0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"oleaut32", module:0x754E0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"oleaut32", module:0x754E0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"oleaut32", module:0x754E0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"oleaut32", module:0x754E0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"gdi32.dll", handle:0x779F0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"gdi32", module:0x779F0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"gdi32", module:0x779F0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"gdi32", module:0x779F0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtOpenSection, status:0x0, hand
le:0x2A4, access:0xF, path:"\KnownDlls32\ws2_32.dll"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x775F0000, zerobits:0x0, commitsize:0x0, viewsize:0x5F000, disposition
:0x1, type:0x800000, protect:0x4, handle:0x2A4, path:"\KnownDlls32\WS2_32.dll"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtClose, status:0x0, handle:0x2
A4
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"ws2_32.dll", handle:0x775F0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"ws2_32", module:0x775F0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"ws2_32", module:0x775F0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"ws2_32", module:0x775F0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"ws2_32", module:0x775F0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"ws2_32", module:0x775F0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"ws2_32", module:0x775F0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrLoadDll, status:0x0, flags:0

x0, module:"rpcrt4.dll", handle:0x77000000


pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"rpcrt4", module:0x77000000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"user32.dll", handle:0x75050000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"user32", module:0x75050000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"user32", module:0x75050000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"user32", module:0x75050000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"user32", module:0x75050000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"user32", module:0x75050000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"user32", module:0x75050000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"user32", module:0x75050000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"user32", module:0x75050000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"user32", module:0x75050000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"user32", module:0x75050000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5A0000, zerobits:0x0, commitsize:0x0, offset:0x220000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x570000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x570000, zerobits:0x0, commitsize:0x0, offset:0x270000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:LOG, func:RecurseRegistryConfig, log:"Du
plicate regkey CurrentVersion will not be added as it is at lower layer."
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5A0000, zerobits:0x0, commitsize:0x0, offset:0x220000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x570000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x570000, zerobits:0x0, commitsize:0x0, offset:0x270000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:LOG, func:NtOpenKey, status:0xC0000034,
handle:0x0, access:0x8, path:"\Registry\Machine\Software\Microsoft\Windows\Curre
ntVersion\SideBySide\AssemblyStorageRoots"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5A0000, zerobits:0x0, commitsize:0x0, offset:0x1E0000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x570000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding directory browser with flags: 2."
pid:4092, tid:2168, tick:0x33D6FC1, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding directory defaults with flags: 2."
pid:4092, tid:2168, tick:0x33D6FC1, lvl:LOG, func:RecurseDirectoryConfig, log:"A

dding directory dictionaries with flags: 2."


pid:4092, tid:2168, tick:0x33D6FC1, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding directory gmp-clearkey with flags: 2."
pid:4092, tid:2168, tick:0x33D6FC1, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding directory uninstall with flags: 2."
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x570000, zerobits:0x0, commitsize:0x0, offset:0x210000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding directory webapprt with flags: 2."
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5A0000, zerobits:0x0, commitsize:0x0, offset:0x1E0000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x570000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:LOG, func:NtQueryAttributesFile, status:
0xC0000034, path:"C:\Program Files (x86)\Mozilla Firefox\firefox.exe.Local\"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtOpenFile, status:0x0, handle:
0x2B0, access:0x100020, iostatus:0x0, information:0x1, share:0x3, options:0x21,
path:"C:\WINDOWS\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5
.82.10586.0_none_811bc0006c44242b"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x20, path:"C:\WINDOWS\WinSxS\x86_microsoft.windows.common-controls_
6595b64144ccf1df_5.82.10586.0_none_811bc0006c44242b\comctl32.dll"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtOpenFile, status:0x0, handle:
0x2B4, access:0x100021, iostatus:0x0, information:0x1, share:0x5, options:0x60,
path:"C:\WINDOWS\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5
.82.10586.0_none_811bc0006c44242b\comctl32.dll"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtCreateSection, status:0x0, ha
ndle:0x2B8, access:0xF, pageattribs:0x10, sectionattribs:0x1000000, file:0x2B4
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x64710000, zerobits:0x0, commitsize:0x0, viewsize:0x92000, disposition
:0x1, type:0x800000, protect:0x4, handle:0x2B8, path:"C:\WINDOWS\WinSxS\x86_micr
osoft.windows.common-controls_6595b64144ccf1df_5.82.10586.0_none_811bc0006c44242
b\comctl32.dll"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtClose, status:0x0, handle:0x2
B8
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtClose, status:0x0, handle:0x2
B4
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"KERNELBASE.DLL", module:0x776F0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x776F0000, name:"FlsAlloc", ordinal:0x0, address:0x777B470
0, image:0x0, caller:0x6471F1B5
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x776F0000, name:"FlsGetValue", ordinal:0x0, address:0x7779
F4E0, image:0x0, caller:0x6471F1C6
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x776F0000, name:"FlsSetValue", ordinal:0x0, address:0x777A
DA10, image:0x0, caller:0x6471F1D7
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x776F0000, name:"FlsFree", ordinal:0x0, address:0x777B61A0
, image:0x0, caller:0x6471F1E8
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x776F0000, name:"EncodePointer", ordinal:0x0, address:0x77
C70070, image:0x0, caller:0x6471ED5D
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x776F0000, name:"EncodePointer", ordinal:0x0, address:0x77

C70070, image:0x0, caller:0x6471ED5D


pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x776F0000, name:"EncodePointer", ordinal:0x0, address:0x77
C70070, image:0x0, caller:0x6471ED5D
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x776F0000, name:"EncodePointer", ordinal:0x0, address:0x77
C70070, image:0x0, caller:0x6471ED5D
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x776F0000, name:"EncodePointer", ordinal:0x0, address:0x77
C70070, image:0x0, caller:0x6471ED5D
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x776F0000, name:"EncodePointer", ordinal:0x0, address:0x77
C70070, image:0x0, caller:0x6471ED5D
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x776F0000, name:"EncodePointer", ordinal:0x0, address:0x77
C70070, image:0x0, caller:0x6471ED5D
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x776F0000, name:"DecodePointer", ordinal:0x0, address:0x77
C6FE50, image:0x0, caller:0x6471ECCC
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x776F0000, name:"DecodePointer", ordinal:0x0, address:0x77
C6FE50, image:0x0, caller:0x6471ECCC
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x776F0000, name:"EncodePointer", ordinal:0x0, address:0x77
C70070, image:0x0, caller:0x6471F0D2
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x776F0000, name:"DecodePointer", ordinal:0x0, address:0x77
C6FE50, image:0x0, caller:0x6471F0E4
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:GetCommandLineA, ret:0x68CBA0,
gle:0x0, cmdline:"\"C:\Program Files (x86)\Mozilla Firefox\firefox.exe\""
pid:4092, tid:2168, tick:0x33D6FC1, lvl:LOG, func:LdrGetDllHandle, status:0xC000
0135, name:"LPK.DLL"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"KERNEL32", module:0x74CD0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74CD0000, name:"ProcessIdToSessionId", ordinal:0x0, addre
ss:0x74CE8FA0, image:0x0, caller:0x647149F9
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x2B8, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246399
0887-1001"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtClose, status:0x0, handle:0x2
B8
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"imm32.dll", handle:0x77670000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"ImmCreateContext", ordinal:0x0, address:0
x7767D5D0, image:0x0, caller:0x64714B09
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"ImmDestroyContext", ordinal:0x0, address:
0x7767D640, image:0x0, caller:0x64714B22
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"ImmNotifyIME", ordinal:0x0, address:0x776
81CB0, image:0x0, caller:0x64714B3B
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"ImmAssociateContext", ordinal:0x0, addres
s:0x77672380, image:0x0, caller:0x64714B54
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"ImmReleaseContext", ordinal:0x0, address:
0x77675430, image:0x0, caller:0x64714B6D
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetProcedureAddressForCaller

, status:0x0, module:0x77670000, name:"ImmGetContext", ordinal:0x0, address:0x77


672D10, image:0x0, caller:0x64714B86
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"ImmGetCompositionStringA", ordinal:0x0, a
ddress:0x7767E280, image:0x0, caller:0x64714B9B
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"ImmSetCompositionStringA", ordinal:0x0, a
ddress:0x7767F0A0, image:0x0, caller:0x64714BB0
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"ImmGetCompositionStringW", ordinal:0x0, a
ddress:0x7767E320, image:0x0, caller:0x64714BC5
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"ImmSetCompositionStringW", ordinal:0x0, a
ddress:0x7767F0D0, image:0x0, caller:0x64714BDA
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"ImmSetCandidateWindow", ordinal:0x0, addr
ess:0x7767EEE0, image:0x0, caller:0x64714BEF
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"comctl32.dll", handle:0x64710000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x20, path:"C:\WINDOWS\WinSxS\x86_microsoft.windows.common-controls_
6595b64144ccf1df_5.82.10586.0_none_811bc0006c44242b\comctl32.DLL"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"comctl32", module:0x64710000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x20, path:"C:\WINDOWS\WinSxS\x86_microsoft.windows.common-controls_
6595b64144ccf1df_5.82.10586.0_none_811bc0006c44242b\comctl32.DLL"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"comctl32", module:0x64710000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x20, path:"C:\WINDOWS\WinSxS\x86_microsoft.windows.common-controls_
6595b64144ccf1df_5.82.10586.0_none_811bc0006c44242b\comctl32.DLL"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"comctl32", module:0x64710000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:LOG, func:NtOpenSection, status:0xC00000
34, handle:0x0, access:0xF, path:"\KnownDlls32\version.dll"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:LOG, func:NtQueryAttributesFile, status:
0xC0000034, path:"C:\Users\i92segoa\Desktop\Firefox SEO\version.dll"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x20, path:"C:\WINDOWS\SYSTEM32\version.dll"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtOpenFile, status:0x0, handle:
0x2B4, access:0x100021, iostatus:0x0, information:0x1, share:0x5, options:0x60,
path:"C:\WINDOWS\SYSTEM32\version.dll"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtCreateSection, status:0x0, ha
ndle:0x2B8, access:0xF, pageattribs:0x10, sectionattribs:0x1000000, file:0x2B4
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x743C0000, zerobits:0x0, commitsize:0x0, viewsize:0x8000, disposition:
0x1, type:0x800000, protect:0x4, handle:0x2B8, path:"C:\WINDOWS\SYSTEM32\version
.dll"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtClose, status:0x0, handle:0x2
B8
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtClose, status:0x0, handle:0x2
B4
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"version.dll", handle:0x743C0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"version", module:0x743C0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"version", module:0x743C0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrLoadDll, status:0x0, flags:0

x0, module:"gdi32.dll", handle:0x779F0000


pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"gdi32.dll", module:0x779F0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"gdi32.dll", module:0x779F0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:LOG, func:NtOpenSection, status:0xC00000
34, handle:0x0, access:0xF, path:"\KnownDlls32\mswsock.dll"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:LOG, func:NtQueryAttributesFile, status:
0xC0000034, path:"C:\Users\i92segoa\Desktop\Firefox SEO\mswsock.dll"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x20, path:"C:\WINDOWS\SYSTEM32\mswsock.dll"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtOpenFile, status:0x0, handle:
0x2B4, access:0x100021, iostatus:0x0, information:0x1, share:0x5, options:0x60,
path:"C:\WINDOWS\SYSTEM32\mswsock.dll"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtCreateSection, status:0x0, ha
ndle:0x2B8, access:0xF, pageattribs:0x10, sectionattribs:0x1000000, file:0x2B4
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x73700000, zerobits:0x0, commitsize:0x0, viewsize:0x4F000, disposition
:0x1, type:0x800000, protect:0x4, handle:0x2B8, path:"C:\WINDOWS\SYSTEM32\mswsoc
k.dll"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtClose, status:0x0, handle:0x2
B8
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtClose, status:0x0, handle:0x2
B4
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"mswsock.dll", handle:0x73700000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"mswsock.dll", module:0x73700000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:LOG, func:NtOpenSection, status:0xC00000
34, handle:0x0, access:0xF, path:"\KnownDlls32\dnsapi.dll"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:LOG, func:NtQueryAttributesFile, status:
0xC0000034, path:"C:\Users\i92segoa\Desktop\Firefox SEO\dnsapi.dll"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x20, path:"C:\WINDOWS\SYSTEM32\dnsapi.dll"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtOpenFile, status:0x0, handle:
0x29C, access:0x100021, iostatus:0x0, information:0x1, share:0x5, options:0x60,
path:"C:\WINDOWS\SYSTEM32\dnsapi.dll"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtCreateSection, status:0x0, ha
ndle:0x2B4, access:0xF, pageattribs:0x10, sectionattribs:0x1000000, file:0x29C
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x72170000, zerobits:0x0, commitsize:0x0, viewsize:0x84000, disposition
:0x1, type:0x800000, protect:0x4, handle:0x2B4, path:"C:\WINDOWS\SYSTEM32\dnsapi
.dll"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtOpenSection, status:0x0, hand
le:0x2B8, access:0xF, path:"\KnownDlls32\NSI.dll"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x77520000, zerobits:0x0, commitsize:0x0, viewsize:0x7000, disposition:
0x1, type:0x800000, protect:0x4, handle:0x2B8, path:"\KnownDlls32\NSI.dll"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtClose, status:0x0, handle:0x2
B8
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtClose, status:0x0, handle:0x2
B4
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtClose, status:0x0, handle:0x2
9C
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"dnsapi.dll", handle:0x72170000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"dnsapi.dll", module:0x72170000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"dnsapi.dll", module:0x72170000

pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na


me:"dnsapi.dll", module:0x72170000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"dnsapi.dll", module:0x72170000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:LOG, func:NtOpenSection, status:0xC00000
34, handle:0x0, access:0xF, path:"\KnownDlls32\httpapi.dll"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:LOG, func:NtQueryAttributesFile, status:
0xC0000034, path:"C:\Users\i92segoa\Desktop\Firefox SEO\httpapi.dll"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x20, path:"C:\WINDOWS\SYSTEM32\httpapi.dll"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtOpenFile, status:0x0, handle:
0x2C4, access:0x100021, iostatus:0x0, information:0x1, share:0x5, options:0x60,
path:"C:\WINDOWS\SYSTEM32\httpapi.dll"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtCreateSection, status:0x0, ha
ndle:0x2C8, access:0xF, pageattribs:0x10, sectionattribs:0x1000000, file:0x2C4
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x74800000, zerobits:0x0, commitsize:0x0, viewsize:0xB000, disposition:
0x1, type:0x800000, protect:0x4, handle:0x2C8, path:"C:\WINDOWS\SYSTEM32\httpapi
.dll"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtClose, status:0x0, handle:0x2
C8
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtClose, status:0x0, handle:0x2
C4
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"httpapi.dll", handle:0x74800000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"httpapi.dll", module:0x74800000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"httpapi.dll", module:0x74800000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"httpapi.dll", module:0x74800000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"httpapi.dll", module:0x74800000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"httpapi.dll", module:0x74800000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"httpapi.dll", module:0x74800000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"httpapi.dll", module:0x74800000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"httpapi.dll", module:0x74800000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtOpenSection, status:0x0, hand
le:0x2C4, access:0xF, path:"\KnownDlls32\crypt32.dll"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x77870000, zerobits:0x0, commitsize:0x0, viewsize:0x179000, dispositio
n:0x1, type:0x800000, protect:0x4, handle:0x2C4, path:"\KnownDlls32\CRYPT32.dll"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtOpenSection, status:0x0, hand
le:0x2C8, access:0xF, path:"\KnownDlls32\MSASN1.dll"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x75250000, zerobits:0x0, commitsize:0x0, viewsize:0xE000, disposition:
0x1, type:0x800000, protect:0x4, handle:0x2C8, path:"\KnownDlls32\MSASN1.dll"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtClose, status:0x0, handle:0x2
C8
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtClose, status:0x0, handle:0x2
C4
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"crypt32.dll", handle:0x77870000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"crypt32.dll", module:0x77870000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na

me:"crypt32.dll", module:0x77870000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"shell32.dll", handle:0x75670000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"shell32.dll", module:0x75670000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"shell32.dll", module:0x75670000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"shell32.dll", module:0x75670000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"shell32.dll", module:0x75670000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"shell32.dll", module:0x75670000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:LOG, func:NtOpenSection, status:0xC00000
34, handle:0x0, access:0xF, path:"\KnownDlls32\mpr.dll"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:LOG, func:NtQueryAttributesFile, status:
0xC0000034, path:"C:\Users\i92segoa\Desktop\Firefox SEO\mpr.dll"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x20, path:"C:\WINDOWS\SYSTEM32\mpr.dll"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtOpenFile, status:0x0, handle:
0x2C8, access:0x100021, iostatus:0x0, information:0x1, share:0x5, options:0x60,
path:"C:\WINDOWS\SYSTEM32\mpr.dll"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtCreateSection, status:0x0, ha
ndle:0x2CC, access:0xF, pageattribs:0x10, sectionattribs:0x1000000, file:0x2C8
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x62CE0000, zerobits:0x0, commitsize:0x0, viewsize:0x16000, disposition
:0x1, type:0x800000, protect:0x4, handle:0x2CC, path:"C:\WINDOWS\SYSTEM32\mpr.dl
l"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtClose, status:0x0, handle:0x2
CC
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtClose, status:0x0, handle:0x2
C8
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x2CC, access:0x20019, path:"\REGISTRY\MACHINE\system\CurrentControlSet\control
\NetworkProvider\HwOrder"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtNotifyChangeKey, status:0x103
, event:0x2C8, iostatus:0x103, information:0x0, filter:0x4, watch:0x0, length:0x
0, async:0x1, handle:0x2CC, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control
\NetworkProvider\HwOrder"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtCreateSemaphore, status:0x0,
handle:0x2D0, access:0x100003, initialcount:0x0, maxcount:0x7FFFFFFF
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtCreateSemaphore, status:0x0,
handle:0x2D4, access:0x100003, initialcount:0x0, maxcount:0x7FFFFFFF
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"mpr.dll", handle:0x62CE0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"mpr.dll", module:0x62CE0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"mpr.dll", module:0x62CE0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"advapi32.dll", handle:0x77B40000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"kernelbase.dll", module:0x776F0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"ntdll.dll", module:0x77C10000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"ntdll.dll", module:0x77C10000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"kernel32.dll", module:0x74CD0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na

me:"kernelbase.dll", module:0x776F0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"kernelbase.dll", module:0x776F0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"advapi32.dll", module:0x77B40000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"advapi32.dll", module:0x77B40000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"shlwapi.dll", handle:0x77BC0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"shlwapi.dll", module:0x77BC0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"advapi32.dll", handle:0x77B40000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"advapi32.dll", module:0x77B40000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"advapi32.dll", module:0x77B40000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"advapi32.dll", module:0x77B40000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"advapi32.dll", module:0x77B40000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"advapi32.dll", module:0x77B40000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"advapi32.dll", module:0x77B40000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"advapi32.dll", module:0x77B40000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"advapi32.dll", module:0x77B40000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"advapi32.dll", module:0x77B40000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"sechost.dll", handle:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"sechost.dll", handle:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na

me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK,
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK,
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK,
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK,
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK,
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK,
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK,
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK,
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK,
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK,
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK,
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK,
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK,
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK,
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK,
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK,
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK,
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK,
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK,
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK,
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK,
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK,
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK,
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK,
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK,
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK,
x0, module:"ole32.dll", handle:0x75580000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK,
me:"ole32.dll", module:0x75580000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK,
me:"ole32.dll", module:0x75580000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK,
me:"ole32.dll", module:0x75580000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK,

func:LdrGetDllHandle, status:0x0, na
func:LdrGetDllHandle, status:0x0, na
func:LdrGetDllHandle, status:0x0, na
func:LdrGetDllHandle, status:0x0, na
func:LdrGetDllHandle, status:0x0, na
func:LdrGetDllHandle, status:0x0, na
func:LdrGetDllHandle, status:0x0, na
func:LdrGetDllHandle, status:0x0, na
func:LdrGetDllHandle, status:0x0, na
func:LdrGetDllHandle, status:0x0, na
func:LdrGetDllHandle, status:0x0, na
func:LdrGetDllHandle, status:0x0, na
func:LdrGetDllHandle, status:0x0, na
func:LdrGetDllHandle, status:0x0, na
func:LdrGetDllHandle, status:0x0, na
func:LdrGetDllHandle, status:0x0, na
func:LdrGetDllHandle, status:0x0, na
func:LdrGetDllHandle, status:0x0, na
func:LdrGetDllHandle, status:0x0, na
func:LdrGetDllHandle, status:0x0, na
func:LdrGetDllHandle, status:0x0, na
func:LdrGetDllHandle, status:0x0, na
func:LdrGetDllHandle, status:0x0, na
func:LdrGetDllHandle, status:0x0, na
func:LdrGetDllHandle, status:0x0, na
func:LdrLoadDll, status:0x0, flags:0
func:LdrGetDllHandle, status:0x0, na
func:LdrGetDllHandle, status:0x0, na
func:LdrGetDllHandle, status:0x0, na
func:LdrGetDllHandle, status:0x0, na

me:"ole32.dll", module:0x75580000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"ole32.dll", module:0x75580000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"ole32.dll", module:0x75580000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"ole32.dll", module:0x75580000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"user32.dll", handle:0x75050000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"user32.dll", module:0x75050000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"user32.dll", module:0x75050000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"user32.dll", module:0x75050000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"user32.dll", module:0x75050000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"user32.dll", module:0x75050000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"user32.dll", module:0x75050000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"user32.dll", module:0x75050000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"user32.dll", module:0x75050000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"user32.dll", module:0x75050000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"user32.dll", module:0x75050000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"user32.dll", module:0x75050000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"user32.dll", module:0x75050000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"user32.dll", module:0x75050000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:LOG, func:InterceptAPI32, log:"Didn't fi
nd method CreateWindowA."
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"user32.dll", module:0x75050000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:LOG, func:InterceptAPI32, log:"Didn't fi
nd method CreateWindowW."
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"ws2_32.dll", handle:0x775F0000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"ws2_32.dll", module:0x775F0000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"ws2_32.dll", module:0x775F0000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"ws2_32.dll", module:0x775F0000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"ws2_32.dll", module:0x775F0000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"ws2_32.dll", module:0x775F0000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"ws2_32.dll", module:0x775F0000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"ws2_32.dll", module:0x775F0000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"ws2_32.dll", module:0x775F0000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetDllHandle, status:0x0, na

me:"ws2_32.dll", module:0x775F0000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"ws2_32.dll", module:0x775F0000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"ws2_32.dll", module:0x775F0000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"ws2_32.dll", module:0x775F0000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"ws2_32.dll", module:0x775F0000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"ws2_32.dll", module:0x775F0000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"ws2_32.dll", module:0x775F0000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"ws2_32.dll", module:0x775F0000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"ws2_32.dll", module:0x775F0000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x570000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5A0000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding directory x64 with flags: 3."
pid:4092, tid:2168, tick:0x33D6FD0, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding directory x86 with flags: 3."
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5A0000, zerobits:0x0, commitsize:0x0, offset:0x1E0000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x570000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x570000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5A0000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x82, path:"C:\Users\i92segoa\Desktop\Firefox SEO\__Xenocode\x86\vmx
.dll"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtOpenFile, status:0x0, handle:
0x2D8, access:0x100021, iostatus:0x0, information:0x0, share:0x5, options:0x60,
path:"C:\Users\i92segoa\Desktop\Firefox SEO\__Xenocode\x86\vmx.dll"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtCreateSection, status:0x0, ha
ndle:0x2E0, access:0xF, pageattribs:0x10, sectionattribs:0x1000000, file:0x2D8
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
E8
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtSetInformationProcess, status
:0x0, class:0x1, length:0x38
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
EC
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x10000000, zerobits:0x0, commitsize:0x0, viewsize:0x175000, dispositio
n:0x1, type:0x800000, protect:0x4, handle:0x2E0, path:"C:\Users\i92segoa\Desktop
\Firefox SEO\__Xenocode\x86\vmx.dll"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:LOG, func:NtOpenSection, status:0xC00000
34, handle:0x0, access:0xF, path:"\KnownDlls32\WININET.dll"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:LOG, func:NtOpenSection, status:0xC00000
34, handle:0x0, access:0xF, path:"\KnownDlls32\Secur32.dll"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
E0

pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2


D8
pid:4092, tid:2168, tick:0x33D6FD0, lvl:LOG, func:NtQueryAttributesFile, status:
0xC0000034, path:"C:\Users\i92segoa\Desktop\Firefox SEO\WININET.dll"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x20, path:"C:\WINDOWS\SYSTEM32\WININET.dll"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtOpenFile, status:0x0, handle:
0x2E4, access:0x100021, iostatus:0x0, information:0x1, share:0x5, options:0x60,
path:"C:\WINDOWS\SYSTEM32\WININET.dll"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtCreateSection, status:0x0, ha
ndle:0x2EC, access:0xF, pageattribs:0x10, sectionattribs:0x1000000, file:0x2E4
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x701C0000, zerobits:0x0, commitsize:0x0, viewsize:0x277000, dispositio
n:0x1, type:0x800000, protect:0x4, handle:0x2EC, path:"C:\WINDOWS\SYSTEM32\WININ
ET.dll"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
EC
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
E4
pid:4092, tid:2168, tick:0x33D6FD0, lvl:LOG, func:NtQueryAttributesFile, status:
0xC0000034, path:"C:\Users\i92segoa\Desktop\Firefox SEO\Secur32.dll"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x20, path:"C:\WINDOWS\SYSTEM32\Secur32.dll"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtOpenFile, status:0x0, handle:
0x2E4, access:0x100021, iostatus:0x0, information:0x1, share:0x5, options:0x60,
path:"C:\WINDOWS\SYSTEM32\Secur32.dll"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtCreateSection, status:0x0, ha
ndle:0x2EC, access:0xF, pageattribs:0x10, sectionattribs:0x1000000, file:0x2E4
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x732C0000, zerobits:0x0, commitsize:0x0, viewsize:0xA000, disposition:
0x1, type:0x800000, protect:0x4, handle:0x2EC, path:"C:\WINDOWS\SYSTEM32\Secur32
.dll"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
EC
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
E4
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x701C0000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x2EC, c
lass:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtSetInformationProcess, status
:0x0, class:0x47, length:0x4
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
EC
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
E8
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
EC
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"kernel32.dll", module:0x74CD0000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74CD0000, name:"FlsAlloc", ordinal:0x0, address:0x74CEA98
0, image:0x0, caller:0x1005CEC3
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74CD0000, name:"FlsFree", ordinal:0x0, address:0x74CF4FF0
, image:0x0, caller:0x1005CED6
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74CD0000, name:"FlsGetValue", ordinal:0x0, address:0x74CE
7570, image:0x0, caller:0x1005CEE9

pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetProcedureAddressForCaller


, status:0x0, module:0x74CD0000, name:"FlsSetValue", ordinal:0x0, address:0x74CE
9E30, image:0x0, caller:0x1005CEFC
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74CD0000, name:"InitializeCriticalSectionEx", ordinal:0x0
, address:0x74CF6740, image:0x0, caller:0x1005CF0F
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74CD0000, name:"CreateSemaphoreExW", ordinal:0x0, address
:0x74CF6700, image:0x0, caller:0x1005CF22
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74CD0000, name:"SetThreadStackGuarantee", ordinal:0x0, ad
dress:0x74CEB040, image:0x0, caller:0x1005CF35
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74CD0000, name:"CreateThreadpoolTimer", ordinal:0x0, addr
ess:0x74CEACE0, image:0x0, caller:0x1005CF48
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74CD0000, name:"SetThreadpoolTimer", ordinal:0x0, address
:0x77C3A8F0, image:0x0, caller:0x1005CF5B
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74CD0000, name:"WaitForThreadpoolTimerCallbacks", ordinal
:0x0, address:0x77C398B0, image:0x0, caller:0x1005CF6E
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74CD0000, name:"CloseThreadpoolTimer", ordinal:0x0, addre
ss:0x77C39130, image:0x0, caller:0x1005CF81
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74CD0000, name:"CreateThreadpoolWait", ordinal:0x0, addre
ss:0x74CEA7B0, image:0x0, caller:0x1005CF94
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74CD0000, name:"SetThreadpoolWait", ordinal:0x0, address:
0x77C7ACA0, image:0x0, caller:0x1005CFA7
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74CD0000, name:"CloseThreadpoolWait", ordinal:0x0, addres
s:0x77C37FA0, image:0x0, caller:0x1005CFBA
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74CD0000, name:"FlushProcessWriteBuffers", ordinal:0x0, a
ddress:0x77C87990, image:0x0, caller:0x1005CFCD
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74CD0000, name:"FreeLibraryWhenCallbackReturns", ordinal:
0x0, address:0x77C7AC60, image:0x0, caller:0x1005CFE0
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74CD0000, name:"GetCurrentProcessorNumber", ordinal:0x0,
address:0x77C6D620, image:0x0, caller:0x1005CFF3
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74CD0000, name:"GetLogicalProcessorInformation", ordinal:
0x0, address:0x74CEAC80, image:0x0, caller:0x1005D006
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74CD0000, name:"CreateSymbolicLinkW", ordinal:0x0, addres
s:0x74D10830, image:0x0, caller:0x1005D019
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74CD0000, name:"SetDefaultDllDirectories", ordinal:0x0, a
ddress:0x77826210, image:0x0, caller:0x1005D02C
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74CD0000, name:"EnumSystemLocalesEx", ordinal:0x0, addres
s:0x74CEFE80, image:0x0, caller:0x1005D03F
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74CD0000, name:"CompareStringEx", ordinal:0x0, address:0x
74CEFF80, image:0x0, caller:0x1005D052
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74CD0000, name:"GetDateFormatEx", ordinal:0x0, address:0x
74D10E00, image:0x0, caller:0x1005D065

pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetProcedureAddressForCaller


, status:0x0, module:0x74CD0000, name:"GetLocaleInfoEx", ordinal:0x0, address:0x
74CEA750, image:0x0, caller:0x1005D078
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74CD0000, name:"GetTimeFormatEx", ordinal:0x0, address:0x
74D11240, image:0x0, caller:0x1005D08B
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74CD0000, name:"GetUserDefaultLocaleName", ordinal:0x0, a
ddress:0x74CEAD60, image:0x0, caller:0x1005D09E
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74CD0000, name:"IsValidLocaleName", ordinal:0x0, address:
0x74D11460, image:0x0, caller:0x1005D0B1
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74CD0000, name:"LCMapStringEx", ordinal:0x0, address:0x74
CE9A10, image:0x0, caller:0x1005D0C4
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74CD0000, name:"GetCurrentPackageId", ordinal:0x0, addres
s:0x777AE140, image:0x0, caller:0x1005D0D7
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:GetCommandLineA, ret:0x68CBA0,
gle:0x0, cmdline:"\"C:\Program Files (x86)\Mozilla Firefox\firefox.exe\""
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x77000000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"Kernel32.dll", handle:0x74CD0000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74CD0000, name:"GetTickCount64", ordinal:0x0, address:0x7
4CE3630, image:0x0, caller:0x1010934B
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"C:\Users\i92segoa\Desktop\Firefox SEO\__Xenocode\x86\vmx.dll", handl
e:0x10000000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"user32.dll", handle:0x75050000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"user32.dll", module:0x75050000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"user32.dll", module:0x75050000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"user32.dll", module:0x75050000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"user32.dll", module:0x75050000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"user32.dll", module:0x75050000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"user32.dll", module:0x75050000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"user32.dll", module:0x75050000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"user32.dll", module:0x75050000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"user32.dll", module:0x75050000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"user32.dll", module:0x75050000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"user32.dll", module:0x75050000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"user32.dll", module:0x75050000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"user32.dll", module:0x75050000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"user32.dll", module:0x75050000

pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetDllHandle, status:0x0, na


me:"user32.dll", module:0x75050000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"user32.dll", module:0x75050000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"user32.dll", module:0x75050000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"user32.dll", module:0x75050000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"user32.dll", module:0x75050000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"user32.dll", module:0x75050000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"user32.dll", module:0x75050000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"user32.dll", module:0x75050000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"kernel32.dll", module:0x74CD0000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"kernel32.dll", module:0x74CD0000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:LOG, func:LdrGetDllHandle, status:0xC000
0135, name:"sxwmon32.dll"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"ntdll.dll", module:0x77C10000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtSetInformationProcess, status
:0x0, class:0xC, length:0x4
pid:4092, tid:2168, tick:0x33D6FD0, lvl:LOG, func:NtQueryAttributesFile, status:
0xC0000034, path:"C:\Users\i92segoa\Desktop\Firefox SEO\data\roaming\modified\@P
ROGRAMFILESX86@\Mozilla Firefox\firefox.exe"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:LOG, func:NtQueryAttributesFile, status:
0xC0000034, path:"C:\Users\i92segoa\Desktop\Firefox SEO\data\roaming\modified\@P
ROGRAMFILESX86@\Mozilla Firefox\firefox.exe.DLL"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtSetInformationProcess, status
:0x0, class:0xC, length:0x4
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:LOG, func:ExtraInit, log:"Finished extra
init. Time consumed so far: 78 ms."
pid:4092, tid:2168, tick:0x33D6FD0, lvl:LOG, func:NtCreateFile, status:0xC000003
A, handle:0x0, access:0x80100080, iostatus:0xC0, information:0xA30055F6, attribs
:0x80, share:0x3, disposition:0x1, options:0x60, path:"C:\_spoon\windowclassexce
ption.txt"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5A0000, zerobits:0x0, commitsize:0x0, offset:0x210000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x570000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x570000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5A0000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:LOG, func:NtOpenFile, status:0xC0000034,
handle:0x0, access:0x100001, iostatus:0x1D0FE0, information:0x100, share:0x7, o
ptions:0x4021, path:"C:\_spoon\"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x2F4, access:0x20019, path:"\Registry\Machine\System\CurrentControlSet\Control\C
omputerName\ActiveComputerName"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtQueryValueKey, status:0x0, na

me:"ComputerName", class:0x1, length:0x80, resultlength:0x50, handle:0x2F4, path


:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\ComputerName\ActiveComputerName
"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
F4
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x2F4, access:0x20019, path:"\Registry\Machine\System\Setup"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"OOBEInProgress", class:0x1, length:0x80, resultlength:0x34, handle:0x2F4, pa
th:"\REGISTRY\MACHINE\SYSTEM\Setup"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
F4
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x2F4, access:0x20019, path:"\Registry\Machine\System\Setup"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"SystemSetupInProgress", class:0x1, length:0x80, resultlength:0x44, handle:0x
2F4, path:"\REGISTRY\MACHINE\SYSTEM\Setup"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
F4
pid:4092, tid:2168, tick:0x33D6FD0, lvl:LOG, func:GetComputerNameExW, ret:0x1, g
le:0xCB, NameType:0x0, lpBuffer:"DESKTOP-OHU1LUJ", lpnSize:0xF
pid:4092, tid:2168, tick:0x33D6FD0, lvl:LOG, func:VmLog, log:"LICENSE: Checking
license."
pid:4092, tid:2168, tick:0x33D6FD0, lvl:LOG, func:VmLog, log:"LICENSE: Checking
expiration if can expire."
pid:4092, tid:2168, tick:0x33D6FD0, lvl:LOG, func:VmLog, log:"LICENSE: Passed."
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x736A0000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtCreateFile, status:0x0, handl
e:0x2F4, access:0x100080, iostatus:0x0, information:0x0, attribs:0x0, share:0x3,
disposition:0x1, options:0x40, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtDeviceIoControlFile, status:0
x105, event:0x2F8, iostatus:0x105, information:0x70, code:0x12001B, inlen:0x3C,
outlen:0x3C, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
F8
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x2F8, iostatus:0x0, information:0x70, code:0x12001B, inlen:0x3C, outl
en:0x3C, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
F8
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x2F8, iostatus:0x0, information:0x50, code:0x120007, inlen:0x30, outl
en:0x4, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
F8
pid:4092, tid:2168, tick:0x33D6FD0, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x2F8, iostatus:0x0, information:0x19E8DC, code:0x12000F, inle
n:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
F8
pid:4092, tid:2168, tick:0x33D6FD0, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x2F8, iostatus:0x0, information:0x19E8DC, code:0x12000F, inle
n:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
F8
pid:4092, tid:2168, tick:0x33D6FD0, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x2F8, iostatus:0x0, information:0x19E8DC, code:0x12000F, inle
n:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2

F8
pid:4092, tid:2168, tick:0x33D6FD0, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x2F8, iostatus:0x0, information:0x19E8DC, code:0x12000F, inle
n:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
F8
pid:4092, tid:2168, tick:0x33D6FD0, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x2F8, iostatus:0x0, information:0x19E8DC, code:0x12000F, inle
n:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
F8
pid:4092, tid:2168, tick:0x33D6FD0, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x2F8, iostatus:0x0, information:0x19E8DC, code:0x12000F, inle
n:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
F8
pid:4092, tid:2168, tick:0x33D6FD0, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x2F8, iostatus:0x0, information:0x19E8DC, code:0x12000F, inle
n:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
F8
pid:4092, tid:2168, tick:0x33D6FD0, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x2F8, iostatus:0x0, information:0x19E8DC, code:0x12000F, inle
n:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
F8
pid:4092, tid:2168, tick:0x33D6FD0, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x2F8, iostatus:0x0, information:0x19E8DC, code:0x12000F, inle
n:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
F8
pid:4092, tid:2168, tick:0x33D6FD0, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x2F8, iostatus:0x0, information:0x19E8DC, code:0x12000F, inle
n:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
F8
pid:4092, tid:2168, tick:0x33D6FD0, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x2F8, iostatus:0x0, information:0x19E8DC, code:0x12000F, inle
n:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
F8
pid:4092, tid:2168, tick:0x33D6FD0, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x2F8, iostatus:0x0, information:0x19E8DC, code:0x12000F, inle
n:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
F8
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x2F8, iostatus:0x0, information:0x68, code:0x12000F, inlen:0x38, outl
en:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
F8
pid:4092, tid:2168, tick:0x33D6FD0, lvl:LOG, func:NtOpenSection, status:0xC00000
34, handle:0x0, access:0xF, path:"\KnownDlls32\dhcpcsvc.DLL"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:LOG, func:NtQueryAttributesFile, status:
0xC0000034, path:"C:\Users\i92segoa\Desktop\Firefox SEO\dhcpcsvc.DLL"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x20, path:"C:\WINDOWS\SYSTEM32\dhcpcsvc.DLL"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtOpenFile, status:0x0, handle:
0x2C0, access:0x100021, iostatus:0x0, information:0x1, share:0x5, options:0x60,
path:"C:\WINDOWS\SYSTEM32\dhcpcsvc.DLL"

pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtCreateSection, status:0x0, ha


ndle:0x2F8, access:0xF, pageattribs:0x10, sectionattribs:0x1000000, file:0x2C0
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x705C0000, zerobits:0x0, commitsize:0x0, viewsize:0x14000, disposition
:0x1, type:0x800000, protect:0x4, handle:0x2F8, path:"C:\WINDOWS\SYSTEM32\dhcpcs
vc.DLL"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
F8
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
C0
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x736A0000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x705C0000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x2F8, access:0x20019, path:"\REGISTRY\MACHINE\System\CurrentControlSet\Service
s\Tcpip\Parameters\Interfaces"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x2FC, iostatus:0x0, information:0x68, code:0x12000F, inlen:0x38, outl
en:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
FC
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x2FC, access:0x1, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\
Parameters\Interfaces\{abd919bb-91ac-4c6c-8277-e2111fefc2db}"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"EnableDhcp", class:0x2, length:0x90, resultlength:0x10, handle:0x2FC, path:"
\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{abd
919bb-91ac-4c6c-8277-e2111fefc2db}"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtSetInformationProcess, status
:0x0, class:0x47, length:0x4
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
F8
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
FC
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtCreateFile, status:0x0, handl
e:0x2FC, access:0x100001, iostatus:0x0, information:0x0, attribs:0x80, share:0x3
, disposition:0x1, options:0x0, path:"\DEVICE\NETBT_TCPIP_{ABD919BB-91AC-4C6C-82
77-E2111FEFC2DB}"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, iostatus:0x0, information:0x0, code:0x21009A, inlen:0x0, outlen:0x3C, handle
:0x2FC, path:"\DEVICE\NETBT_TCPIP_{ABD919BB-91AC-4C6C-8277-E2111FEFC2DB}"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
FC
pid:4092, tid:2168, tick:0x33D6FD0, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x2FC, iostatus:0x736A18B0, information:0x0, code:0x12000F, in
len:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
FC
pid:4092, tid:2168, tick:0x33D6FD0, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x2FC, iostatus:0x736A18B0, information:0x0, code:0x12000F, in
len:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
FC
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x2FC, iostatus:0x0, information:0x68, code:0x12000F, inlen:0x38, outl
en:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
FC
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle

:0x2FC, access:0x20019, path:"\REGISTRY\MACHINE\System\CurrentControlSet\Service


s\Tcpip\Parameters\Interfaces"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x2F8, iostatus:0x0, information:0x68, code:0x12000F, inlen:0x38, outl
en:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
F8
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x2F8, access:0x1, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\
Parameters\Interfaces\{c81413b6-ce1c-47be-a023-4451f682ef7b}"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"EnableDhcp", class:0x2, length:0x90, resultlength:0x10, handle:0x2F8, path:"
\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{c81
413b6-ce1c-47be-a023-4451f682ef7b}"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
FC
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
F8
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtCreateFile, status:0x0, handl
e:0x2F8, access:0x100001, iostatus:0x0, information:0x0, attribs:0x80, share:0x3
, disposition:0x1, options:0x0, path:"\DEVICE\NETBT_TCPIP_{C81413B6-CE1C-47BE-A0
23-4451F682EF7B}"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, iostatus:0x0, information:0x0, code:0x21009A, inlen:0x0, outlen:0x3C, handle
:0x2F8, path:"\DEVICE\NETBT_TCPIP_{C81413B6-CE1C-47BE-A023-4451F682EF7B}"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
F8
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x2F8, iostatus:0x0, information:0x68, code:0x12000F, inlen:0x38, outl
en:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
F8
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x2F8, access:0x20019, path:"\REGISTRY\MACHINE\System\CurrentControlSet\Service
s\Tcpip\Parameters\Interfaces"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x2FC, iostatus:0x0, information:0x68, code:0x12000F, inlen:0x38, outl
en:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
FC
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x2FC, access:0x1, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\
Parameters\Interfaces\{1d1269e9-273b-4f67-a226-1f36daec17e1}"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"EnableDhcp", class:0x2, length:0x90, resultlength:0x10, handle:0x2FC, path:"
\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{1d1
269e9-273b-4f67-a226-1f36daec17e1}"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
F8
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
FC
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtCreateFile, status:0x0, handl
e:0x2FC, access:0x100001, iostatus:0x0, information:0x0, attribs:0x80, share:0x3
, disposition:0x1, options:0x0, path:"\DEVICE\NETBT_TCPIP_{1D1269E9-273B-4F67-A2
26-1F36DAEC17E1}"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, iostatus:0x0, information:0x0, code:0x21009A, inlen:0x0, outlen:0x3C, handle
:0x2FC, path:"\DEVICE\NETBT_TCPIP_{1D1269E9-273B-4F67-A226-1F36DAEC17E1}"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
FC

pid:4092, tid:2168, tick:0x33D6FD0, lvl:LOG, func:NtDeviceIoControlFile, status:


0xC0000225, event:0x2FC, iostatus:0x736A18B0, information:0x0, code:0x12000F, in
len:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
FC
pid:4092, tid:2168, tick:0x33D6FD0, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x2FC, iostatus:0x736A18B0, information:0x0, code:0x12000F, in
len:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
FC
pid:4092, tid:2168, tick:0x33D6FD0, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x2FC, iostatus:0x736A18B0, information:0x0, code:0x12000F, in
len:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
FC
pid:4092, tid:2168, tick:0x33D6FD0, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x2FC, iostatus:0x736A18B0, information:0x0, code:0x12000F, in
len:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
FC
pid:4092, tid:2168, tick:0x33D6FD0, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x2FC, iostatus:0x736A18B0, information:0x0, code:0x12000F, in
len:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
FC
pid:4092, tid:2168, tick:0x33D6FD0, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x2FC, iostatus:0x736A18B0, information:0x0, code:0x12000F, in
len:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
FC
pid:4092, tid:2168, tick:0x33D6FD0, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x2FC, iostatus:0x736A18B0, information:0x0, code:0x12000F, in
len:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
FC
pid:4092, tid:2168, tick:0x33D6FD0, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x2FC, iostatus:0x736A18B0, information:0x0, code:0x12000F, in
len:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
FC
pid:4092, tid:2168, tick:0x33D6FD0, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x2FC, iostatus:0x736A18B0, information:0x0, code:0x12000F, in
len:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
FC
pid:4092, tid:2168, tick:0x33D6FD0, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x2FC, iostatus:0x736A18B0, information:0x0, code:0x12000F, in
len:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
FC
pid:4092, tid:2168, tick:0x33D6FD0, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x2FC, iostatus:0x736A18B0, information:0x0, code:0x12000F, in
len:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
FC
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x2FC, iostatus:0x0, information:0x68, code:0x12000F, inlen:0x38, outl
en:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
FC

pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle


:0x304, access:0x20019, path:"\REGISTRY\MACHINE\System\CurrentControlSet\Service
s\Tcpip\Parameters\Interfaces"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x308, iostatus:0x0, information:0x68, code:0x12000F, inlen:0x38, outl
en:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
08
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x308, access:0x1, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\
Parameters\Interfaces\{326e8084-72c2-41be-908e-dcd81f25f732}"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"EnableDhcp", class:0x2, length:0x90, resultlength:0x10, handle:0x308, path:"
\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{326
e8084-72c2-41be-908e-dcd81f25f732}"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
04
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
08
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"rpcrt4.dll", handle:0x77000000
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x308, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Rpc"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"MaxRpcSize", class:0x2, length:0x90, resultlength:0x201C8, handle:0x
308, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Rpc"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
08
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtQuerySecurityObject, status:
0xC0000023, class:0x17, length:0x0, requiredlength:0xE8, handle:0x304, path:"\RP
C Control"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtQuerySecurityObject, status:0
x0, class:0x17, length:0xE8, requiredlength:0xE8, handle:0x304, path:"\RPC Contr
ol"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x30C, c
lass:0xA, length:0x38, returnlength:0x38
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x30C, c
lass:0x4, length:0x48, returnlength:0x20
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x30C, c
lass:0x19, length:0x4C, returnlength:0x14, sid:"S-1-16-8192", attributes:0x60
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:New_NtQueryInformationToken::<
lambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0xC0000023, token:
0x30C, class:0x5, length:0x0, returnlength:0x20
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x30C, c
lass:0x5, length:0x20, returnlength:0x20
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:New_NtQueryInformationToken::<
lambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0xC0000023, token:
0x30C, class:0x6, length:0x0, returnlength:0x60
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x30C, c
lass:0x6, length:0x60, returnlength:0x60
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF

FC, class:0x29, length:0x48, returnlength:0x4


pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x30C, c
lass:0x29, length:0x48, returnlength:0x4
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x30C, c
lass:0xA, length:0x38, returnlength:0x38
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x30C, c
lass:0x4, length:0x48, returnlength:0x20
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x30C, c
lass:0x19, length:0x4C, returnlength:0x14, sid:"S-1-16-8192", attributes:0x60
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:New_NtQueryInformationToken::<
lambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0xC0000023, token:
0x30C, class:0x5, length:0x0, returnlength:0x20
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x30C, c
lass:0x5, length:0x20, returnlength:0x20
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:New_NtQueryInformationToken::<
lambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0xC0000023, token:
0x30C, class:0x6, length:0x0, returnlength:0x60
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x30C, c
lass:0x6, length:0x60, returnlength:0x60
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FC, class:0x29, length:0x48, returnlength:0x4
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x30C, c
lass:0x29, length:0x48, returnlength:0x4
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
04
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
0C
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies\Microsof
t\Windows NT\Rpc"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x314, access:0x1, path:"\REGISTRY\MACHINE\Software\Microsoft\Rpc"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"IdleTimerWindow", class:0x2, length:0x90, resultlength:0x19DF38, han
dle:0x314, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Rpc"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
14
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtDuplicateObject, status:0x0,
targethandle:0x318, access:0x0, inherit:0x0, options:0x2, handle:0xFFFFFFFE
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtCreateFile, status:0x0, handl
e:0x320, access:0x100001, iostatus:0x0, information:0x0, attribs:0x80, share:0x3
, disposition:0x1, options:0x0, path:"\DEVICE\NETBT_TCPIP_{326E8084-72C2-41BE-90
8E-DCD81F25F732}"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, iostatus:0x0, information:0x0, code:0x21009A, inlen:0x0, outlen:0x3C, handle
:0x320, path:"\DEVICE\NETBT_TCPIP_{326E8084-72C2-41BE-908E-DCD81F25F732}"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
20
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtDeviceIoControlFile, status:0

x0, event:0x320, iostatus:0x0, information:0x68, code:0x12000F, inlen:0x38, outl


en:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
20
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x320, access:0x20019, path:"\REGISTRY\MACHINE\System\CurrentControlSet\Service
s\Tcpip\Parameters\Interfaces"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x324, iostatus:0x0, information:0x68, code:0x12000F, inlen:0x38, outl
en:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
24
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x324, access:0x1, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\
Parameters\Interfaces\{fe6ca5f4-30ac-4d3c-9c85-547684bf338a}"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"EnableDhcp", class:0x2, length:0x90, resultlength:0x10, handle:0x324, path:"
\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{fe6
ca5f4-30ac-4d3c-9c85-547684bf338a}"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
20
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
24
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtCreateFile, status:0x0, handl
e:0x324, access:0x100001, iostatus:0x0, information:0x0, attribs:0x80, share:0x3
, disposition:0x1, options:0x0, path:"\DEVICE\NETBT_TCPIP_{FE6CA5F4-30AC-4D3C-9C
85-547684BF338A}"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, iostatus:0x0, information:0x0, code:0x21009A, inlen:0x0, outlen:0x3C, handle
:0x324, path:"\DEVICE\NETBT_TCPIP_{FE6CA5F4-30AC-4D3C-9C85-547684BF338A}"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
24
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x324, iostatus:0x736A18B0, information:0x0, code:0x12000F, in
len:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
24
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x324, iostatus:0x736A18B0, information:0x0, code:0x12000F, in
len:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
24
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x324, iostatus:0x736A18B0, information:0x0, code:0x12000F, in
len:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
24
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x324, iostatus:0x736A18B0, information:0x0, code:0x12000F, in
len:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
24
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x324, iostatus:0x736A18B0, information:0x0, code:0x12000F, in
len:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
24
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x324, iostatus:0x736A18B0, information:0x0, code:0x12000F, in
len:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"

pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3


24
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x324, iostatus:0x0, information:0x70, code:0x12001B, inlen:0x3C, outl
en:0x3C, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
24
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x324, iostatus:0x0, information:0x70, code:0x12001B, inlen:0x3C, outl
en:0x3C, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
24
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x324, iostatus:0x0, information:0x70, code:0x12001B, inlen:0x3C, outl
en:0x3C, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
24
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x324, iostatus:0x0, information:0x70, code:0x12001B, inlen:0x3C, outl
en:0x3C, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
24
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x324, access:0x20019, path:"\REGISTRY\MACHINE\SYSTEM\CurrentControlSet\Service
s\Tcpip\Linkage"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtQueryValueKey, status:0x8000
0005, name:"Bind", class:0x2, length:0x90, resultlength:0x2A0, handle:0x324, pat
h:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Linkage"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtQueryValueKey, status:0x8000
0005, name:"Bind", class:0x2, length:0x90, resultlength:0x2A0, handle:0x324, pat
h:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Linkage"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Bind", class:0x2, length:0x2A0, resultlength:0x2A0, handle:0x324, path:"\REG
ISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Linkage"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtQueryValueKey, status:0x8000
0005, name:"Bind", class:0x2, length:0x90, resultlength:0x2A0, handle:0x324, pat
h:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Linkage"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtQueryValueKey, status:0x8000
0005, name:"Bind", class:0x2, length:0x90, resultlength:0x2A0, handle:0x324, pat
h:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Linkage"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Bind", class:0x2, length:0x2A0, resultlength:0x2A0, handle:0x324, path:"\REG
ISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Linkage"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
24
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtOpenSection, status:0xC00000
34, handle:0x0, access:0xF, path:"\KnownDlls32\CRYPTSP.dll"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtQueryAttributesFile, status:
0xC0000034, path:"C:\Users\i92segoa\Desktop\Firefox SEO\CRYPTSP.dll"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x20, path:"C:\WINDOWS\SYSTEM32\CRYPTSP.dll"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtOpenFile, status:0x0, handle:
0x324, access:0x100021, iostatus:0x0, information:0x1, share:0x5, options:0x60,
path:"C:\WINDOWS\SYSTEM32\CRYPTSP.dll"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtCreateSection, status:0x0, ha
ndle:0x320, access:0xF, pageattribs:0x10, sectionattribs:0x1000000, file:0x324
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x70650000, zerobits:0x0, commitsize:0x0, viewsize:0x13000, disposition
:0x1, type:0x800000, protect:0x4, handle:0x320, path:"C:\WINDOWS\SYSTEM32\CRYPTS
P.dll"

pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3


20
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
24
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x77B40000
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x320, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\Microsoft\Cryptography\
Defaults\Provider\Microsoft Base Cryptographic Provider v1.0"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Type", class:0x2, length:0x90, resultlength:0x10, handle:0x320, path:"\REGIS
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Micros
oft Base Cryptographic Provider v1.0"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Image Path", class:0x2, length:0x90, resultlength:0x4E, handle:0x320, path:"
\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\
Microsoft Base Cryptographic Provider v1.0"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Image Path", class:0x2, length:0x90, resultlength:0x4E, handle:0x320, path:"
\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\
Microsoft Base Cryptographic Provider v1.0"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Image Path", class:0x2, length:0x90, resultlength:0x4E, handle:0x320, path:"
\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\
Microsoft Base Cryptographic Provider v1.0"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Image Path", class:0x2, length:0x90, resultlength:0x4E, handle:0x320, path:"
\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\
Microsoft Base Cryptographic Provider v1.0"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtOpenSection, status:0xC00000
34, handle:0x0, access:0xF, path:"\KnownDlls32\rsaenh.dll"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x20, path:"C:\WINDOWS\system32\rsaenh.dll"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtOpenFile, status:0x0, handle:
0x328, access:0x100021, iostatus:0x0, information:0x1, share:0x5, options:0x60,
path:"C:\WINDOWS\system32\rsaenh.dll"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtCreateSection, status:0x0, ha
ndle:0x32C, access:0xF, pageattribs:0x10, sectionattribs:0x1000000, file:0x328
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x705E0000, zerobits:0x0, commitsize:0x0, viewsize:0x2F000, disposition
:0x1, type:0x800000, protect:0x4, handle:0x32C, path:"C:\WINDOWS\system32\rsaenh
.dll"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtOpenSection, status:0xC00000
34, handle:0x0, access:0xF, path:"\KnownDlls32\bcrypt.dll"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
2C
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
28
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtQueryAttributesFile, status:
0xC0000034, path:"C:\Users\i92segoa\Desktop\Firefox SEO\bcrypt.dll"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x20, path:"C:\WINDOWS\SYSTEM32\bcrypt.dll"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtOpenFile, status:0x0, handle:
0x328, access:0x100021, iostatus:0x0, information:0x1, share:0x5, options:0x60,
path:"C:\WINDOWS\SYSTEM32\bcrypt.dll"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtCreateSection, status:0x0, ha
ndle:0x32C, access:0xF, pageattribs:0x10, sectionattribs:0x1000000, file:0x328
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x72B20000, zerobits:0x0, commitsize:0x0, viewsize:0x1B000, disposition
:0x1, type:0x800000, protect:0x4, handle:0x32C, path:"C:\WINDOWS\SYSTEM32\bcrypt

.dll"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
2C
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
28
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtCreateSemaphore, status:0x0,
handle:0x334, access:0x100003, initialcount:0x0, maxcount:0x7FFFFFFF
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtCreateSemaphore, status:0x0,
handle:0x338, access:0x100003, initialcount:0x0, maxcount:0x7FFFFFFF
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtOpenFile, status:0x0, handle:
0x340, access:0x100003, iostatus:0x0, information:0x0, share:0x7, options:0x20,
path:"\Device\KsecDD"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, iostatus:0x0, information:0x0, code:0x390402, inlen:0x68, outlen:0x8, handle
:0x340, path:"\Device\KsecDD"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"C:\WINDOWS\system32\rsaenh.dll", handle:0x705E0000
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPAcquireContext", ordinal:0x0, address:0
x705E4CA0, image:0x0, caller:0x706542D4
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPReleaseContext", ordinal:0x0, address:0
x705E8930, image:0x0, caller:0x706542D4
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPGenKey", ordinal:0x0, address:0x705E600
0, image:0x0, caller:0x706542D4
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPDeriveKey", ordinal:0x0, address:0x705F
ADE0, image:0x0, caller:0x706542D4
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPDestroyKey", ordinal:0x0, address:0x705
E6D30, image:0x0, caller:0x706542D4
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPSetKeyParam", ordinal:0x0, address:0x70
5FC7D0, image:0x0, caller:0x706542D4
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPGetKeyParam", ordinal:0x0, address:0x70
5E8800, image:0x0, caller:0x706542D4
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPExportKey", ordinal:0x0, address:0x705E
5B80, image:0x0, caller:0x706542D4
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPImportKey", ordinal:0x0, address:0x705E
7440, image:0x0, caller:0x706542D4
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPEncrypt", ordinal:0x0, address:0x705F98
E0, image:0x0, caller:0x706542D4
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPDecrypt", ordinal:0x0, address:0x705E95
A0, image:0x0, caller:0x706542D4
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPCreateHash", ordinal:0x0, address:0x705
E8040, image:0x0, caller:0x706542D4
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPHashData", ordinal:0x0, address:0x705E6
A30, image:0x0, caller:0x706542D4
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPHashSessionKey", ordinal:0x0, address:0
x705FA650, image:0x0, caller:0x706542D4
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrGetProcedureAddressForCaller

, status:0x0, module:0x705E0000, name:"CPDestroyHash", ordinal:0x0, address:0x70


5E5A30, image:0x0, caller:0x706542D4
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPSignHash", ordinal:0x0, address:0x705FF
0B0, image:0x0, caller:0x706542D4
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPVerifySignature", ordinal:0x0, address:
0x705E6290, image:0x0, caller:0x706542D4
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPGenRandom", ordinal:0x0, address:0x705E
8C10, image:0x0, caller:0x706542D4
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPGetUserKey", ordinal:0x0, address:0x705
EB040, image:0x0, caller:0x706542D4
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPSetProvParam", ordinal:0x0, address:0x7
05FD280, image:0x0, caller:0x706542D4
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPGetProvParam", ordinal:0x0, address:0x7
05FB820, image:0x0, caller:0x706542D4
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPSetHashParam", ordinal:0x0, address:0x7
05E6EC0, image:0x0, caller:0x706542D4
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPGetHashParam", ordinal:0x0, address:0x7
05E6550, image:0x0, caller:0x706542D4
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPDuplicateKey", ordinal:0x0, address:0x7
05FB620, image:0x0, caller:0x70654303
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPDuplicateHash", ordinal:0x0, address:0x
705FA4C0, image:0x0, caller:0x70654303
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x34C, access:0x20119, path:"\REGISTRY\MACHINE\Software\Policies\Microsoft\Cryp
tography"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"PrivKeyCacheMaxItems", class:0x2, length:0x90, resultlength:0x11, ha
ndle:0x34C, path:"\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Cryptography"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"PrivKeyCachePurgeIntervalSeconds", class:0x2, length:0x90, resultlen
gth:0x20, handle:0x34C, path:"\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Cryp
tography"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"PrivateKeyLifetimeSeconds", class:0x2, length:0x90, resultlength:0x2
0, handle:0x34C, path:"\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Cryptograph
y"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
4C
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x34C, c
lass:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
4C
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x34C, access:0x20119, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptography"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"MachineGuid", class:0x2, length:0x90, resultlength:0x56, handle:0x34C, path:
"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Cryptography"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"MachineGuid", class:0x2, length:0x90, resultlength:0x56, handle:0x34C, path:

"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Cryptography"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"MachineGuid", class:0x2, length:0x90, resultlength:0x56, handle:0x34C, path:
"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Cryptography"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"MachineGuid", class:0x2, length:0x90, resultlength:0x56, handle:0x34C, path:
"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Cryptography"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
4C
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptog
raphy\Offload"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x34C, c
lass:0x1, length:0x400, returnlength:0x24, sid:"S-1-5-21-2360094602-2602383397-2
463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
4C
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x705E0000
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptog
raphy\DESHashSessionKeyBackward"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
20
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, iostatus:0x0, information:0xE0, code:0x390402, inlen:0x40, outlen:0x180, han
dle:0x340, path:"\Device\KsecDD"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"C:\WINDOWS\system32\bcryptprimitives.dll", handle:0x74AB0000
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74AB0000, name:"GetHashInterface", ordinal:0x0, address:0
x74AC98C0, image:0x0, caller:0x72B3146B
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
20
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtDeviceIoControlFile, status:0
x105, event:0x320, iostatus:0x105, information:0x70, code:0x12001B, inlen:0x3C,
outlen:0x3C, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
20
pid:4092, tid:9004, tick:0x33D6FE0, lvl:LOG, func:BaseThreadInitThunk, log:"New
thread started (via BaseThreadInitThunk) at address: 0x10039100, parameter: 0x10
14D36C"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x320, iostatus:0x0, information:0x70, code:0x12001B, inlen:0x3C, outl
en:0x3C, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
20
pid:4092, tid:9004, tick:0x33D6FE0, lvl:LOG, func:NtOpenSection, status:0xC00000
34, handle:0x0, access:0xF, path:"\KnownDlls32\iertutil.dll"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x320, iostatus:0x0, information:0x50, code:0x120007, inlen:0x30, outl
en:0x4, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
20
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x320, iostatus:0x0, information:0x19E8D4, code:0x12000F, inle
n:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
20

pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtDeviceIoControlFile, status:


0xC0000225, event:0x320, iostatus:0x0, information:0x19E8D4, code:0x12000F, inle
n:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
20
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x320, iostatus:0x0, information:0x19E8D4, code:0x12000F, inle
n:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
20
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x320, iostatus:0x0, information:0x19E8D4, code:0x12000F, inle
n:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
20
pid:4092, tid:9004, tick:0x33D6FE0, lvl:LOG, func:NtQueryAttributesFile, status:
0xC0000034, path:"C:\Users\i92segoa\Desktop\Firefox SEO\iertutil.dll"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x320, iostatus:0x0, information:0x19E8D4, code:0x12000F, inle
n:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
20
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x320, iostatus:0x0, information:0x19E8D4, code:0x12000F, inle
n:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
20
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x320, iostatus:0x0, information:0x19E8D4, code:0x12000F, inle
n:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
20
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x320, iostatus:0x0, information:0x19E8D4, code:0x12000F, inle
n:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
20
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x320, iostatus:0x0, information:0x19E8D4, code:0x12000F, inle
n:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
20
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x320, iostatus:0x0, information:0x19E8D4, code:0x12000F, inle
n:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
20
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x20, path:"C:\WINDOWS\SYSTEM32\iertutil.dll"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x320, iostatus:0x0, information:0x19E8D4, code:0x12000F, inle
n:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
20
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x320, iostatus:0x0, information:0x19E8D4, code:0x12000F, inle
n:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
20
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtDeviceIoControlFile, status:0

x0, event:0x320, iostatus:0x0, information:0x68, code:0x12000F, inlen:0x38, outl


en:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
20
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x320, access:0x20019, path:"\REGISTRY\MACHINE\System\CurrentControlSet\Service
s\Tcpip\Parameters\Interfaces"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x354, iostatus:0x0, information:0x68, code:0x12000F, inlen:0x38, outl
en:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
54
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x354, access:0x1, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\
Parameters\Interfaces\{abd919bb-91ac-4c6c-8277-e2111fefc2db}"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtOpenFile, status:0x0, handle:
0x34C, access:0x100021, iostatus:0x0, information:0x1, share:0x5, options:0x60,
path:"C:\WINDOWS\SYSTEM32\iertutil.dll"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"EnableDhcp", class:0x2, length:0x90, resultlength:0x10, handle:0x354, path:"
\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{abd
919bb-91ac-4c6c-8277-e2111fefc2db}"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
20
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtCreateSection, status:0x0, ha
ndle:0x350, access:0xF, pageattribs:0x10, sectionattribs:0x1000000, file:0x34C
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
54
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x72810000, zerobits:0x0, commitsize:0x0, viewsize:0x2CF000, dispositio
n:0x1, type:0x800000, protect:0x4, handle:0x350, path:"C:\WINDOWS\SYSTEM32\iertu
til.dll"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtCreateFile, status:0x0, handl
e:0x354, access:0x100001, iostatus:0x0, information:0x0, attribs:0x80, share:0x3
, disposition:0x1, options:0x0, path:"\DEVICE\NETBT_TCPIP_{ABD919BB-91AC-4C6C-82
77-E2111FEFC2DB}"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, iostatus:0x0, information:0x0, code:0x21009A, inlen:0x0, outlen:0x3C, handle
:0x354, path:"\DEVICE\NETBT_TCPIP_{ABD919BB-91AC-4C6C-8277-E2111FEFC2DB}"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
54
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x354, iostatus:0x736A18B0, information:0x0, code:0x12000F, in
len:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
54
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x354, iostatus:0x736A18B0, information:0x0, code:0x12000F, in
len:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
54
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x354, iostatus:0x0, information:0x68, code:0x12000F, inlen:0x38, outl
en:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
54
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
50
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
4C

pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle


:0x354, access:0x20019, path:"\REGISTRY\MACHINE\System\CurrentControlSet\Service
s\Tcpip\Parameters\Interfaces"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x320, iostatus:0x0, information:0x68, code:0x12000F, inlen:0x38, outl
en:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
20
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x320, access:0x1, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\
Parameters\Interfaces\{c81413b6-ce1c-47be-a023-4451f682ef7b}"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"EnableDhcp", class:0x2, length:0x90, resultlength:0x10, handle:0x320, path:"
\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{c81
413b6-ce1c-47be-a023-4451f682ef7b}"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
54
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
20
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtSetInformationProcess, status
:0x0, class:0x23, length:0x28
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtCreateFile, status:0x0, handl
e:0x320, access:0x100001, iostatus:0x0, information:0x0, attribs:0x80, share:0x3
, disposition:0x1, options:0x0, path:"\DEVICE\NETBT_TCPIP_{C81413B6-CE1C-47BE-A0
23-4451F682EF7B}"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, iostatus:0x0, information:0x0, code:0x21009A, inlen:0x0, outlen:0x3C, handle
:0x320, path:"\DEVICE\NETBT_TCPIP_{C81413B6-CE1C-47BE-A023-4451F682EF7B}"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
20
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x320, iostatus:0x0, information:0x68, code:0x12000F, inlen:0x38, outl
en:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
20
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x701C0000
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x320, access:0x20019, path:"\REGISTRY\MACHINE\System\CurrentControlSet\Service
s\Tcpip\Parameters\Interfaces"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"ntdll.dll", module:0x77C10000
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x354, iostatus:0x0, information:0x68, code:0x12000F, inlen:0x38, outl
en:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77C10000, name:"RtlGetDeviceFamilyInfoEnum", ordinal:0x0,
address:0x77C7B110, image:0x0, caller:0x72A1504F
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
54
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x354, access:0x1, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\
Parameters\Interfaces\{1d1269e9-273b-4f67-a226-1f36daec17e1}"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x350, c
lass:0xA, length:0x38, returnlength:0x38
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"EnableDhcp", class:0x2, length:0x90, resultlength:0x10, handle:0x354, path:"
\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{1d1
269e9-273b-4f67-a226-1f36daec17e1}"

pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:New_NtQueryInformationToken::<l


ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x350, c
lass:0x3, length:0x1F8, returnlength:0x40
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
20
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
50
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
54
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x701C0000
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtCreateFile, status:0x0, handl
e:0x354, access:0x100001, iostatus:0x0, information:0x0, attribs:0x80, share:0x3
, disposition:0x1, options:0x0, path:"\DEVICE\NETBT_TCPIP_{1D1269E9-273B-4F67-A2
26-1F36DAEC17E1}"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtOpenEvent, status:0x0, handle
:0x350, access:0x1, path:"\SECURITY\LSA_AUTHENTICATION_INITIALIZED"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, iostatus:0x0, information:0x0, code:0x21009A, inlen:0x0, outlen:0x3C, handle
:0x354, path:"\DEVICE\NETBT_TCPIP_{1D1269E9-273B-4F67-A226-1F36DAEC17E1}"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
50
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
54
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x354, iostatus:0x736A18B0, information:0x0, code:0x12000F, in
len:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtDuplicateObject, status:0x0,
targethandle:0x35C, access:0x0, inherit:0x0, options:0x2, handle:0xFFFFFFFE
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
54
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x354, iostatus:0x736A18B0, information:0x0, code:0x12000F, in
len:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
54
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x354, iostatus:0x736A18B0, information:0x0, code:0x12000F, in
len:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
54
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x354, iostatus:0x736A18B0, information:0x0, code:0x12000F, in
len:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
54
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x354, iostatus:0x736A18B0, information:0x0, code:0x12000F, in
len:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
54
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x354, iostatus:0x736A18B0, information:0x0, code:0x12000F, in
len:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
54
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtDeviceIoControlFile, status:

0xC0000225, event:0x354, iostatus:0x736A18B0, information:0x0, code:0x12000F, in


len:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
54
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x354, iostatus:0x736A18B0, information:0x0, code:0x12000F, in
len:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
54
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x354, iostatus:0x736A18B0, information:0x0, code:0x12000F, in
len:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
54
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"sspicli.dll", handle:0x74940000
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x354, iostatus:0x736A18B0, information:0x0, code:0x12000F, in
len:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
54
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x354, iostatus:0x736A18B0, information:0x0, code:0x12000F, in
len:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
54
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x354, iostatus:0x0, information:0x68, code:0x12000F, inlen:0x38, outl
en:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
54
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x776F0000
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x354, access:0x20019, path:"\REGISTRY\MACHINE\System\CurrentControlSet\Service
s\Tcpip\Parameters\Interfaces"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x320, iostatus:0x0, information:0x68, code:0x12000F, inlen:0x38, outl
en:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
20
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x320, access:0x1, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\
Parameters\Interfaces\{326e8084-72c2-41be-908e-dcd81f25f732}"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"EnableDhcp", class:0x2, length:0x90, resultlength:0x10, handle:0x320, path:"
\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{326
e8084-72c2-41be-908e-dcd81f25f732}"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
54
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
20
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x368, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtCreateFile, status:0x0, handl

e:0x320, access:0x100001, iostatus:0x0, information:0x0, attribs:0x80, share:0x3


, disposition:0x1, options:0x0, path:"\DEVICE\NETBT_TCPIP_{326E8084-72C2-41BE-90
8E-DCD81F25F732}"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5A0000, zerobits:0x0, commitsize:0x0, offset:0x210000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, iostatus:0x0, information:0x0, code:0x21009A, inlen:0x0, outlen:0x3C, handle
:0x320, path:"\DEVICE\NETBT_TCPIP_{326E8084-72C2-41BE-908E-DCD81F25F732}"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x570000
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
20
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x320, iostatus:0x0, information:0x68, code:0x12000F, inlen:0x38, outl
en:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
20
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x570000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5A0000
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x320, access:0x20019, path:"\REGISTRY\MACHINE\System\CurrentControlSet\Service
s\Tcpip\Parameters\Interfaces"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:LOG, func:RecurseRegistryConfig, log:"Du
plicate regkey Windows will not be added as it is at lower layer."
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x354, iostatus:0x0, information:0x68, code:0x12000F, inlen:0x38, outl
en:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
54
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5A0000, zerobits:0x0, commitsize:0x0, offset:0x210000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x570000
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x354, access:0x1, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\
Parameters\Interfaces\{fe6ca5f4-30ac-4d3c-9c85-547684bf338a}"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"EnableDhcp", class:0x2, length:0x90, resultlength:0x10, handle:0x354, path:"
\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{fe6
ca5f4-30ac-4d3c-9c85-547684bf338a}"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x570000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
20
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5A0000
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
54
pid:4092, tid:9004, tick:0x33D6FE0, lvl:LOG, func:RecurseRegistryConfig, log:"Du
plicate regkey CurrentVersion will not be added as it is at lower layer."
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtCreateFile, status:0x0, handl
e:0x354, access:0x100001, iostatus:0x0, information:0x0, attribs:0x80, share:0x3
, disposition:0x1, options:0x0, path:"\DEVICE\NETBT_TCPIP_{FE6CA5F4-30AC-4D3C-9C
85-547684BF338A}"

pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtMapViewOfSection, status:0x0,


address:0x5A0000, zerobits:0x0, commitsize:0x0, offset:0x210000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, iostatus:0x0, information:0x0, code:0x21009A, inlen:0x0, outlen:0x3C, handle
:0x354, path:"\DEVICE\NETBT_TCPIP_{FE6CA5F4-30AC-4D3C-9C85-547684BF338A}"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x570000
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
54
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x354, iostatus:0x736A18B0, information:0x0, code:0x12000F, in
len:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x570000, zerobits:0x0, commitsize:0x0, offset:0x220000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
54
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5A0000
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x354, iostatus:0x736A18B0, information:0x0, code:0x12000F, in
len:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
54
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5A0000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x354, iostatus:0x736A18B0, information:0x0, code:0x12000F, in
len:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x570000
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
54
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x354, iostatus:0x736A18B0, information:0x0, code:0x12000F, in
len:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:LOG, func:RecurseRegistryConfig, log:"Du
plicate regkey Explorer will not be added as it is at lower layer."
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
54
pid:4092, tid:9004, tick:0x33D6FE0, lvl:LOG, func:RecurseRegistryConfig, log:"Du
plicate regkey Internet Settings will not be added as it is at lower layer."
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x354, iostatus:0x736A18B0, information:0x0, code:0x12000F, in
len:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
54
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x354, iostatus:0x736A18B0, information:0x0, code:0x12000F, in
len:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
54
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x354, iostatus:0x0, information:0x70, code:0x12001B, inlen:0x3C, outl
en:0x3C, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
54
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtMapViewOfSection, status:0x0,

address:0x570000, zerobits:0x0, commitsize:0x0, offset:0x220000, viewsize:0x100


00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x354, iostatus:0x0, information:0x70, code:0x12001B, inlen:0x3C, outl
en:0x3C, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5A0000
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
54
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5A0000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x570000
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x354, iostatus:0x0, information:0x70, code:0x12001B, inlen:0x3C, outl
en:0x3C, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
54
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x370, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x354, iostatus:0x0, information:0x70, code:0x12001B, inlen:0x3C, outl
en:0x3C, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"SyncMode5", class:0x2, length:0x90, resultlength:0x10, handle:0x370,
path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\Software\Mi
crosoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
54
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x354, access:0x20019, path:"\REGISTRY\MACHINE\SYSTEM\CurrentControlSet\Service
s\Tcpip\Linkage"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x374, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\Curre
ntVersion\Internet Settings\5.0\Cache"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtQueryValueKey, status:0x8000
0005, name:"Bind", class:0x2, length:0x90, resultlength:0x2A0, handle:0x354, pat
h:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Linkage"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"SessionStartTimeDefaultDeltaSecs", class:0x2, length:0x90, resultlen
gth:0x10, handle:0x374, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\W
indows\CurrentVersion\Internet Settings\5.0\Cache"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtQueryValueKey, status:0x8000
0005, name:"Bind", class:0x2, length:0x90, resultlength:0x2A0, handle:0x354, pat
h:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Linkage"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x378, c
lass:0x19, length:0x64, returnlength:0x14, sid:"S-1-16-8192", attributes:0x60
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
78
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Bind", class:0x2, length:0x2A0, resultlength:0x2A0, handle:0x354, path:"\REG
ISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Linkage"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x701C0000
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtQueryValueKey, status:0x8000
0005, name:"Bind", class:0x2, length:0x90, resultlength:0x2A0, handle:0x354, pat
h:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Linkage"

pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtQueryValueKey, status:0x8000


0005, name:"Bind", class:0x2, length:0x90, resultlength:0x2A0, handle:0x354, pat
h:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Linkage"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Bind", class:0x2, length:0x2A0, resultlength:0x2A0, handle:0x354, path:"\REG
ISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Linkage"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x76B00000
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
54
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x378, c
lass:0x1, length:0x4C, returnlength:0x24, sid:"S-1-5-21-2360094602-2602383397-24
63990887-1001", attributes:0x0
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
78
pid:4092, tid:9004, tick:0x33D6FE0, lvl:WRN, func:New_NtQueryInformationToken::<
lambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0xC0000024, class:
0x1, length:0x40, returnlength:0xFFFFFFF8
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x354, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\Microsoft\Cryptography\
Defaults\Provider\Microsoft Base Cryptographic Provider v1.0"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:WRN, func:New_NtQueryInformationToken::<
lambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0xC0000024, class:
0x1D, length:0x4, returnlength:0x0
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Type", class:0x2, length:0x90, resultlength:0x10, handle:0x354, path:"\REGIS
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Micros
oft Base Cryptographic Provider v1.0"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x76B00000
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Image Path", class:0x2, length:0x90, resultlength:0x4E, handle:0x354, path:"
\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\
Microsoft Base Cryptographic Provider v1.0"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Image Path", class:0x2, length:0x90, resultlength:0x4E, handle:0x354, path:"
\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\
Microsoft Base Cryptographic Provider v1.0"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Image Path", class:0x2, length:0x90, resultlength:0x4E, handle:0x354, path:"
\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\
Microsoft Base Cryptographic Provider v1.0"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Image Path", class:0x2, length:0x90, resultlength:0x4E, handle:0x354, path:"
\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\
Microsoft Base Cryptographic Provider v1.0"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"C:\WINDOWS\system32\rsaenh.dll", handle:0x705E0000
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPAcquireContext", ordinal:0x0, address:0
x705E4CA0, image:0x0, caller:0x706542D4
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPReleaseContext", ordinal:0x0, address:0
x705E8930, image:0x0, caller:0x706542D4
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPGenKey", ordinal:0x0, address:0x705E600
0, image:0x0, caller:0x706542D4
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPDeriveKey", ordinal:0x0, address:0x705F

ADE0, image:0x0, caller:0x706542D4


pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPDestroyKey", ordinal:0x0, address:0x705
E6D30, image:0x0, caller:0x706542D4
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPSetKeyParam", ordinal:0x0, address:0x70
5FC7D0, image:0x0, caller:0x706542D4
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPGetKeyParam", ordinal:0x0, address:0x70
5E8800, image:0x0, caller:0x706542D4
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPExportKey", ordinal:0x0, address:0x705E
5B80, image:0x0, caller:0x706542D4
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPImportKey", ordinal:0x0, address:0x705E
7440, image:0x0, caller:0x706542D4
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtOpenSection, status:0x0, hand
le:0x37C, access:0x6, path:"\Sessions\1\BaseNamedObjects\windows_shell_global_co
unters"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPEncrypt", ordinal:0x0, address:0x705F98
E0, image:0x0, caller:0x706542D4
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPDecrypt", ordinal:0x0, address:0x705E95
A0, image:0x0, caller:0x706542D4
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPCreateHash", ordinal:0x0, address:0x705
E8040, image:0x0, caller:0x706542D4
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPHashData", ordinal:0x0, address:0x705E6
A30, image:0x0, caller:0x706542D4
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPHashSessionKey", ordinal:0x0, address:0
x705FA650, image:0x0, caller:0x706542D4
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x570000, zerobits:0x0, commitsize:0x0, offset:0x0, viewsize:0x1000, di
sposition:0x1, type:0x0, protect:0x4, handle:0x37C, path:"\Sessions\1\BaseNamedO
bjects\windows_shell_global_counters"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPDestroyHash", ordinal:0x0, address:0x70
5E5A30, image:0x0, caller:0x706542D4
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPSignHash", ordinal:0x0, address:0x705FF
0B0, image:0x0, caller:0x706542D4
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPVerifySignature", ordinal:0x0, address:
0x705E6290, image:0x0, caller:0x706542D4
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPGenRandom", ordinal:0x0, address:0x705E
8C10, image:0x0, caller:0x706542D4
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPGetUserKey", ordinal:0x0, address:0x705
EB040, image:0x0, caller:0x706542D4
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5B0000, zerobits:0x0, commitsize:0x0, offset:0x270000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPSetProvParam", ordinal:0x0, address:0x7
05FD280, image:0x0, caller:0x706542D4
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrGetProcedureAddressForCaller

, status:0x0, module:0x705E0000, name:"CPGetProvParam", ordinal:0x0, address:0x7


05FB820, image:0x0, caller:0x706542D4
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5A0000
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPSetHashParam", ordinal:0x0, address:0x7
05E6EC0, image:0x0, caller:0x706542D4
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPGetHashParam", ordinal:0x0, address:0x7
05E6550, image:0x0, caller:0x706542D4
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPDuplicateKey", ordinal:0x0, address:0x7
05FB620, image:0x0, caller:0x70654303
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPDuplicateHash", ordinal:0x0, address:0x
705FA4C0, image:0x0, caller:0x70654303
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x378, c
lass:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
78
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x380, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\Curre
ntVersion\Explorer\FolderDescriptions"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x378, access:0x20119, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptography"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"MachineGuid", class:0x2, length:0x90, resultlength:0x56, handle:0x378, path:
"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Cryptography"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x76B00000
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"MachineGuid", class:0x2, length:0x90, resultlength:0x56, handle:0x378, path:
"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Cryptography"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"MachineGuid", class:0x2, length:0x90, resultlength:0x56, handle:0x378, path:
"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Cryptography"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"MachineGuid", class:0x2, length:0x90, resultlength:0x56, handle:0x378, path:
"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Cryptography"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x388, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\W
indows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007C
AEDCF9D}"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
78
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
80
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Category", class:0x2, length:0x90, resultlength:0x10, handle:0x388, path:"\R
EGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\F
olderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptog
raphy\Offload"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Name", class:0x2, length:0x90, resultlength:0x18, handle:0x388, path:"\REGIS
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Folde
rDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:New_NtQueryInformationToken::<l

ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x378, c


lass:0x1, length:0x400, returnlength:0x24, sid:"S-1-5-21-2360094602-2602383397-2
463990887-1001", attributes:0x0
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ParentFolder", class:0x2, length:0x90, resultlength:0x5A, handle:0x388, path
:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explor
er\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
78
pid:4092, tid:9004, tick:0x33D6FE0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Description", class:0x2, length:0x90, resultlength:0x5A, handle:0x38
8, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion
\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"RelativePath", class:0x2, length:0x90, resultlength:0x44, handle:0x388, path
:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explor
er\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptog
raphy\DESHashSessionKeyBackward"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
54
pid:4092, tid:9004, tick:0x33D6FE0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"ParsingName", class:0x2, length:0x90, resultlength:0x44, handle:0x38
8, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion
\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"InfoTip", class:0x2, length:0x90, resultlength:0x44, handle:0x388, p
ath:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Exp
lorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"LocalizedName", class:0x2, length:0x90, resultlength:0x44, handle:0x
388, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersi
on\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
54
pid:4092, tid:9004, tick:0x33D6FE0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Icon", class:0x2, length:0x90, resultlength:0x44, handle:0x388, path
:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explor
er\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Security", class:0x2, length:0x90, resultlength:0x44, handle:0x388,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Ex
plorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}"
pid:4092, tid:4644, tick:0x33D6FE0, lvl:LOG, func:BaseThreadInitThunk, log:"New
thread started (via BaseThreadInitThunk) at address: 0x100390E0, parameter: 0x10
14D398"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"StreamResource", class:0x2, length:0x90, resultlength:0x44, handle:0
x388, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVers
ion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:ShellExecuteFile, log:"Launchi
ng startup file C:\Program Files (x86)\Mozilla Firefox\firefox.exe, verb open, p
arams , cur-dir C:\Users\i92segoa\Desktop\Firefox SEO\, Wait for Return 2"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"StreamResourceType", class:0x2, length:0x90, resultlength:0x44, hand
le:0x388, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Current
Version\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x75670000

pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtQueryValueKey, status:0x0, na


me:"LocalRedirectOnly", class:0x2, length:0x90, resultlength:0x10, handle:0x388,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\E
xplorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Roamable", class:0x2, length:0x90, resultlength:0x10, handle:0x388,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Ex
plorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5A0000, zerobits:0x0, commitsize:0x0, offset:0x220000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:9004, tick:0x33D6FE0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"PreCreate", class:0x2, length:0x90, resultlength:0x10, handle:0x388,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\E
xplorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5B0000
pid:4092, tid:9004, tick:0x33D6FE0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Stream", class:0x2, length:0x90, resultlength:0x10, handle:0x388, pa
th:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Expl
orer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"PublishExpandedPath", class:0x2, length:0x90, resultlength:0x10, han
dle:0x388, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Curren
tVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x354, access:0x1, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVe
rsion\Policies\Explorer"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DefinitionFlags", class:0x2, length:0x90, resultlength:0x10, handle:
0x388, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVer
sion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"EnableShellExecuteHooks", class:0x2, length:0x90, resultlength:0x0,
handle:0x354, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Windows\CurrentVersion\
Policies\Explorer"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
54
pid:4092, tid:9004, tick:0x33D6FE0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Attributes", class:0x2, length:0x90, resultlength:0x10, handle:0x388
, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\
Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"FolderTypeID", class:0x2, length:0x90, resultlength:0x10, handle:0x3
88, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersio
n\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"InitFolderHandler", class:0x2, length:0x90, resultlength:0x10, handl
e:0x388, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentV
ersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x75670000
pid:4092, tid:9004, tick:0x33D6FE0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Micro
soft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85
-6007CAEDCF9D}\PropertyBag"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3

88
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5B0000, zerobits:0x0, commitsize:0x0, offset:0x210000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5A0000
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5A0000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x10, path:"C:\Users\i92segoa\Desktop\Firefox SEO\"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5B0000
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x75670000
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x388, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24639908
87-1001\Software\Microsoft\Windows\CurrentVersion\Explorer"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5B0000, zerobits:0x0, commitsize:0x0, offset:0x210000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5A0000
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5A0000, zerobits:0x0, commitsize:0x0, offset:0x220000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5B0000
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtQueryAttributesFile, status:
0xC0000034, path:"C:\WINDOWS\system32\rpcss.dll"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:LdrGetDllHandle, status:0xC000
0135, name:"C:\WINDOWS\system32\rpcss.dll"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5B0000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5A0000
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x74DC0000
pid:4092, tid:9004, tick:0x33D6FE0, lvl:LOG, func:RecurseRegistryConfig, log:"Du
plicate regkey UserAssist will not be added as it is at lower layer."
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x380, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24639908
87-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\K
nownFolders"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x74DC0000
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
80
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5A0000, zerobits:0x0, commitsize:0x0, offset:0x220000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5B0000
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5B0000, zerobits:0x0, commitsize:0x0, offset:0x270000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78

pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtUnmapViewOfSection, status:0x


0, address:0x5A0000
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtOpenSection, status:0xC00000
34, handle:0x0, access:0xF, path:"\KnownDlls32\uxtheme.dll"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x380, access:0x2000000, path:"\REGISTRY\USER"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x320, access:0x20019, path:"\REGISTRY\USER\.DEFAULT"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x358, access:0x20019, path:"\REGISTRY\USER\.DEFAULT\Software\Microsoft\Windows
\CurrentVersion\Explorer\User Shell Folders"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
20
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Cache", class:0x2, length:0x90, resultlength:0x7C, handle:0x358, path:"\REGI
STRY\USER\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell
Folders"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x20, path:"C:\WINDOWS\system32\uxtheme.dll"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x320, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows NT\Cu
rrentVersion\ProfileList"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Default", class:0x2, length:0x90, resultlength:0x44, handle:0x320, path:"\RE
GISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\ProfileList"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Default", class:0x2, length:0x90, resultlength:0x44, handle:0x320, path:"\RE
GISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\ProfileList"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
20
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
58
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtOpenFile, status:0x0, handle:
0x38C, access:0x100021, iostatus:0x0, information:0x1, share:0x5, options:0x60,
path:"C:\WINDOWS\system32\uxtheme.dll"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x358, c
lass:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtCreateSection, status:0x0, ha
ndle:0x390, access:0xF, pageattribs:0x10, sectionattribs:0x1000000, file:0x38C
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x320, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24639908
87-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x71930000, zerobits:0x0, commitsize:0x0, viewsize:0x75000, disposition
:0x1, type:0x800000, protect:0x4, handle:0x390, path:"C:\WINDOWS\system32\uxthem
e.dll"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\K
nownFolders"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
20
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x384, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246399
0887-1001"

pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3


90
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
8C
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x38C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folder
s"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
84
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"C:\WINDOWS\system32\uxtheme.dll", handle:0x71930000
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Cache", class:0x2, length:0x90, resultlength:0x84, handle:0x38C, path:"\REGI
STRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Wind
ows\CurrentVersion\Explorer\User Shell Folders"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x71930000, name:"ThemeInitApiHook", ordinal:0x0, address:0
x71953160, image:0x0, caller:0x7506F4C6
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
58
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
8C
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtOpenProcess, status:0x0, hand
le:0x38C, access:0x400, processid:0xFFC, threadid:0x0, path:""
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
8C
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x358, c
lass:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
58
pid:4092, tid:9004, tick:0x33D6FE0, lvl:LOG, func:New_NtQueryInformationToken::<
lambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0xC0000023, token:
0x358, class:0x19, length:0x0, returnlength:0x14
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x358, c
lass:0x19, length:0x14, returnlength:0x14, sid:"S-1-16-8192", attributes:0x60
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
58
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtOpenProcess, status:0x0, hand
le:0x358, access:0x400, processid:0xFFC, threadid:0x0, path:""
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
58
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x38C, c
lass:0x12, length:0x4, returnlength:0x4
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
8C
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x38C, c
lass:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-2602383397-24
63990887-1001", attributes:0x0
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
8C
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"user32.dll", handle:0x75050000
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:CreateWindowExW, ret:0x108EA, g
le:0x0, parent:0xFFFFFFFD, class:"", window:"OleMainThreadWndName"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:LdrGetProcedureAddressForCaller

, status:0x0, module:0x75050000, name:"IsImmersiveProcess", ordinal:0x0, address


:0x7506FEA0, image:0x0, caller:0x72A15666
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x75670000
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x75670000
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x74B20000
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\Software\Policies\Microsoft\Wi
ndows\Explorer"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtOpenFile, status:0x0, handle:
0x38C, access:0x100000, iostatus:0x0, information:0x0, share:0x0, options:0x8000
21, path:"C:\WINDOWS"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtQueryVolumeInformationFile, s
tatus:0x0, iostatus:0x0, information:0x18, length:0x18, class:0x3, handle:0x38C,
path:"C:\WINDOWS"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\Software\Policies\Microsoft\Windows\Explorer"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
8C
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5A0000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5B0000
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5B0000, zerobits:0x0, commitsize:0x0, offset:0x1E0000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5A0000
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5A0000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5B0000
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x358, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Internet Explorer\Main"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"FrameTabWindow", class:0x2, length:0x90, resultlength:0x0, handle:0x
358, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\Softwar
e\Microsoft\Internet Explorer\Main"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5B0000, zerobits:0x0, commitsize:0x0, offset:0x270000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5A0000
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x398, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Internet Expl
orer\Main"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"FrameTabWindow", class:0x2, length:0x90, resultlength:0x10, handle:0
x398, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\M
ain"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtCreateFile, status:0x0, handl
e:0x39C, access:0x100081, iostatus:0x0, information:0x1, attribs:0x0, share:0x7,
disposition:0x1, options:0x4020, path:"C:\Program Files (x86)\Mozilla Firefox"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:LOG, func:NtQueryValueKey, status:0xC000

0034, name:"FrameMerging", class:0x2, length:0x90, resultlength:0x0, handle:0x35


8, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\Software\
Microsoft\Internet Explorer\Main"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:WRN, func:NtQueryInformationFile, status
:0xC000000D, iostatus:0x19EEC8, information:0x0, length:0x74, class:0x37, handle
:0x39C, path:"C:\Program Files (x86)\Mozilla Firefox"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"FrameMerging", class:0x2, length:0x90, resultlength:0x0, handle:0x39
8, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main
"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"SessionMerging", class:0x2, length:0x90, resultlength:0x0, handle:0x
358, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\Softwar
e\Microsoft\Internet Explorer\Main"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"SessionMerging", class:0x2, length:0x90, resultlength:0x0, handle:0x
398, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Ma
in"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"AdminTabProcs", class:0x2, length:0x90, resultlength:0x0, handle:0x3
58, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\Software
\Microsoft\Internet Explorer\Main"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"AdminTabProcs", class:0x2, length:0x90, resultlength:0x0, handle:0x3
98, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Mai
n"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtQueryDirectoryFile, status:0x
0, iostatus:0x0, information:0x88, length:0x278, class:0x25, single:0x3DB001, ma
sk:"firefox.exe", restart:0x1, handle:0x39C, path:"C:\Program Files (x86)\Mozill
a Firefox"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:LOG, func:New_NtQueryInformationToken::<
lambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0xC0000023, token:
0x3A4, class:0x19, length:0x0, returnlength:0x14
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
9C
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x3A4, c
lass:0x19, length:0x14, returnlength:0x14, sid:"S-1-16-8192", attributes:0x60
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
A4
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x3A4, c
lass:0x12, length:0x4, returnlength:0x4
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
A4
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtOpenSection, status:0xC00000
34, handle:0x0, access:0xF, path:"\KnownDlls32\PROPSYS.dll"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies\Microsof
t\Internet Explorer\Main"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001\Software\Policies\Microsoft\Internet Explorer\Main"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtQueryAttributesFile, status:
0xC0000034, path:"C:\Users\i92segoa\Desktop\Firefox SEO\PROPSYS.dll"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"TabProcGrowth", class:0x2, length:0x90, resultlength:0x0, handle:0x3
58, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\Software
\Microsoft\Internet Explorer\Main"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:LOG, func:NtQueryValueKey, status:0xC000

0034, name:"TabProcGrowth", class:0x2, length:0x90, resultlength:0x0, handle:0x3


98, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Mai
n"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"TabProcGrowth", class:0x2, length:0x90, resultlength:0x0, handle:0x3
58, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\Software
\Microsoft\Internet Explorer\Main"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x20, path:"C:\WINDOWS\SYSTEM32\PROPSYS.dll"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"TabProcGrowth", class:0x2, length:0x90, resultlength:0x0, handle:0x3
98, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Mai
n"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\Software\Policies\Microsoft\Wi
ndows\Explorer"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtOpenFile, status:0x0, handle:
0x39C, access:0x100021, iostatus:0x0, information:0x1, share:0x5, options:0x60,
path:"C:\WINDOWS\SYSTEM32\PROPSYS.dll"
pid:4092, tid:9004, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\Software\Policies\Microsoft\Windows\Explorer"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtCreateSection, status:0x0, ha
ndle:0x384, access:0xF, pageattribs:0x10, sectionattribs:0x1000000, file:0x39C
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x3A4, c
lass:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x717E0000, zerobits:0x0, commitsize:0x0, viewsize:0x14B000, dispositio
n:0x1, type:0x800000, protect:0x4, handle:0x384, path:"C:\WINDOWS\SYSTEM32\PROPS
YS.dll"
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x3A8, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\Curre
ntVersion\Explorer\FolderDescriptions"
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x3AC, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\W
indows\CurrentVersion\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7
F157091}"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x3
84
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x3
A8
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x3
9C
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Category", class:0x2, length:0x90, resultlength:0x10, handle:0x3AC, path:"\R
EGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\F
olderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}"
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Name", class:0x2, length:0x90, resultlength:0x28, handle:0x3AC, path:"\REGIS
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Folde
rDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}"
pid:4092, tid:9004, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"ParentFolder", class:0x2, length:0x90, resultlength:0x10, handle:0x3
AC, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersio
n\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}"
pid:4092, tid:9004, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Description", class:0x2, length:0x90, resultlength:0x10, handle:0x3A
C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion
\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}"

pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na


me:"RelativePath", class:0x2, length:0x90, resultlength:0x28, handle:0x3AC, path
:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explor
er\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}"
pid:4092, tid:9004, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"ParsingName", class:0x2, length:0x90, resultlength:0x28, handle:0x3A
C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion
\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x75670000
pid:4092, tid:9004, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"InfoTip", class:0x2, length:0x90, resultlength:0x28, handle:0x3AC, p
ath:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Exp
lorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x717E0000
pid:4092, tid:9004, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"LocalizedName", class:0x2, length:0x90, resultlength:0x28, handle:0x
3AC, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersi
on\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}"
pid:4092, tid:9004, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Icon", class:0x2, length:0x90, resultlength:0x28, handle:0x3AC, path
:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explor
er\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x77BC0000
pid:4092, tid:9004, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Security", class:0x2, length:0x90, resultlength:0x28, handle:0x3AC,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Ex
plorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x77BC0000
pid:4092, tid:9004, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"StreamResource", class:0x2, length:0x90, resultlength:0x28, handle:0
x3AC, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVers
ion\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}"
pid:4092, tid:9004, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"StreamResourceType", class:0x2, length:0x90, resultlength:0x28, hand
le:0x3AC, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Current
Version\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x384, access:0x1, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVe
rsion\Policies\Explorer"
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"LocalRedirectOnly", class:0x2, length:0x90, resultlength:0x10, handle:0x3AC,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\E
xplorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"NoPropertiesMyComputer", class:0x2, length:0x90, resultlength:0x19EF
F0, handle:0x384, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Windows\CurrentVers
ion\Policies\Explorer"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x3
84
pid:4092, tid:9004, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Roamable", class:0x2, length:0x90, resultlength:0x10, handle:0x3AC,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Ex
plorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}"
pid:4092, tid:9004, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"PreCreate", class:0x2, length:0x90, resultlength:0x10, handle:0x3AC,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\E

xplorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"
pid:4092, tid:9004, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Stream", class:0x2, length:0x90, resultlength:0x10, handle:0x3AC, pa
th:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Expl
orer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}"
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"PublishExpandedPath", class:0x2, length:0x90, resultlength:0x10, handle:0x3A
C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion
\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x384, access:0x1, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVe
rsion\Policies\Explorer"
pid:4092, tid:9004, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DefinitionFlags", class:0x2, length:0x90, resultlength:0x10, handle:
0x3AC, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVer
sion\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"NoPropertiesRecycleBin", class:0x2, length:0x90, resultlength:0x19EF
F0, handle:0x384, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Windows\CurrentVers
ion\Policies\Explorer"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x3
84
pid:4092, tid:9004, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Attributes", class:0x2, length:0x90, resultlength:0x10, handle:0x3AC
, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\
Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"
pid:4092, tid:9004, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"FolderTypeID", class:0x2, length:0x90, resultlength:0x10, handle:0x3
AC, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersio
n\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}"
pid:4092, tid:9004, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"InitFolderHandler", class:0x2, length:0x90, resultlength:0x10, handl
e:0x3AC, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentV
ersion\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x384, access:0x1, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVe
rsion\Policies\Explorer"
pid:4092, tid:9004, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Micro
soft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55
-7B8E7F157091}\PropertyBag"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"NoControlPanel", class:0x2, length:0x90, resultlength:0x0, handle:0x
384, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Windows\CurrentVersion\Policies\
Explorer"
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x3
AC
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x3
84
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x384, access:0x1, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVe

rsion\Policies\Explorer"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"NoSetFolders", class:0x2, length:0x90, resultlength:0x0, handle:0x38
4, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Windows\CurrentVersion\Policies\Ex
plorer"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x3
84
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x3AC, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24639908
87-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1"
pid:4092, tid:9004, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\K
nownFolders"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x3
AC
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x384, access:0x1, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVe
rsion\Policies\Explorer"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"NoInternetIcon", class:0x2, length:0x90, resultlength:0x19EFF0, hand
le:0x384, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Windows\CurrentVersion\Poli
cies\Explorer"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x3
84
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x3B4, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246399
0887-1001"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x9, path:"\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\Cur
rentVersion\ShellCompatibility\Applications\firefox.exe"
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x3B8, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folder
s"
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x3
B4
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Local AppData", class:0x2, length:0x90, resultlength:0x44, handle:0x3B8, pat
h:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Micros
oft\Windows\CurrentVersion\Explorer\User Shell Folders"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x384, access:0x1, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVe
rsion\Explorer\Desktop\NameSpace"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"ValidateRegItems", class:0x2, length:0x90, resultlength:0x19F114, ha
ndle:0x384, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Curre
ntVersion\Explorer\Desktop\NameSpace"
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x3
A4

pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x3


84
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x3
B8
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x3B8, c
lass:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x384, access:0x1, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVe
rsion\Explorer\Desktop\NameSpace"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"MonitorRegistry", class:0x2, length:0x90, resultlength:0x10, handle:0x384, p
ath:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Exp
lorer\Desktop\NameSpace"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x3
84
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x3A4, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\Curre
ntVersion\Explorer\FolderDescriptions"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x76B00000
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x3AC, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\W
indows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA331
7B67173}"
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x3
A4
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Category", class:0x2, length:0x90, resultlength:0x10, handle:0x3AC, path:"\R
EGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\F
olderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x384, access:0x1, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVe
rsion\Policies\Explorer"
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Name", class:0x2, length:0x90, resultlength:0x1C, handle:0x3AC, path:"\REGIS
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Folde
rDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"NoCommonGroups", class:0x2, length:0x90, resultlength:0x19F000, hand
le:0x384, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Windows\CurrentVersion\Poli
cies\Explorer"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x3
84
pid:4092, tid:9004, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"ParentFolder", class:0x2, length:0x90, resultlength:0x10, handle:0x3
AC, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersio
n\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}"
pid:4092, tid:9004, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Description", class:0x2, length:0x90, resultlength:0x10, handle:0x3A
C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion
\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"
pid:4092, tid:9004, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"RelativePath", class:0x2, length:0x90, resultlength:0x10, handle:0x3
AC, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersio
n\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:LdrResolveDelayLoadedAPI, statu

s:0x0, module:0x76B00000
pid:4092, tid:9004, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"ParsingName", class:0x2, length:0x90, resultlength:0x10, handle:0x3A
C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion
\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}"
pid:4092, tid:9004, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"InfoTip", class:0x2, length:0x90, resultlength:0x10, handle:0x3AC, p
ath:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Exp
lorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x76B00000
pid:4092, tid:9004, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"LocalizedName", class:0x2, length:0x90, resultlength:0x10, handle:0x
3AC, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersi
on\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x76B00000
pid:4092, tid:9004, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Icon", class:0x2, length:0x90, resultlength:0x10, handle:0x3AC, path
:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explor
er\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x76B00000
pid:4092, tid:9004, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Security", class:0x2, length:0x90, resultlength:0x10, handle:0x3AC,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Ex
plorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:9004, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"StreamResource", class:0x2, length:0x90, resultlength:0x10, handle:0
x3AC, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVers
ion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}"
pid:4092, tid:9004, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"StreamResourceType", class:0x2, length:0x90, resultlength:0x10, hand
le:0x3AC, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Current
Version\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}"
pid:4092, tid:9004, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"LocalRedirectOnly", class:0x2, length:0x90, resultlength:0x10, handl
e:0x3AC, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentV
ersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}"
pid:4092, tid:9004, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Roamable", class:0x2, length:0x90, resultlength:0x10, handle:0x3AC,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Ex
plorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5A0000, zerobits:0x0, commitsize:0x0, offset:0x210000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5B0000
pid:4092, tid:9004, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"PreCreate", class:0x2, length:0x90, resultlength:0x10, handle:0x3AC,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\E
xplorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5B0000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:9004, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000

0034, name:"Stream", class:0x2, length:0x90, resultlength:0x10, handle:0x3AC, pa


th:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Expl
orer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5A0000
pid:4092, tid:9004, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"PublishExpandedPath", class:0x2, length:0x90, resultlength:0x10, han
dle:0x3AC, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Curren
tVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x384, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001_Classes"
pid:4092, tid:9004, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DefinitionFlags", class:0x2, length:0x90, resultlength:0x10, handle:
0x3AC, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVer
sion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5A0000, zerobits:0x0, commitsize:0x0, offset:0x210000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:9004, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Attributes", class:0x2, length:0x90, resultlength:0x10, handle:0x3AC
, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\
Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5B0000
pid:4092, tid:9004, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"FolderTypeID", class:0x2, length:0x90, resultlength:0x10, handle:0x3
AC, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersio
n\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5B0000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:9004, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"InitFolderHandler", class:0x2, length:0x90, resultlength:0x10, handl
e:0x3AC, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentV
ersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5A0000
pid:4092, tid:9004, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Micro
soft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE
-EA3317B67173}\PropertyBag"
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x3
AC
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x3AC, c
lass:0x1, length:0x40, returnlength:0x24, sid:"S-1-5-21-2360094602-2602383397-24
63990887-1001", attributes:0x0
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x76B00000
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x3A4, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows NT\Cu
rrentVersion\ProfileList\S-1-5-21-2360094602-2602383397-2463990887-1001"
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ProfileImagePath", class:0x2, length:0x90, resultlength:0x30, handle:0x3A4,
path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\ProfileList
\S-1-5-21-2360094602-2602383397-2463990887-1001"
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ProfileImagePath", class:0x2, length:0x90, resultlength:0x30, handle:0x3A4,
path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\ProfileList

\S-1-5-21-2360094602-2602383397-2463990887-1001"
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x3
A4
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x3
AC
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x3
B8
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x76B00000
pid:4092, tid:9004, tick:0x33D6FF0, lvl:LOG, func:NtCreateFile, status:0xC000003
5, handle:0x0, access:0x100001, iostatus:0xDD, information:0xBD20DC, attribs:0x8
0, share:0x3, disposition:0x2, options:0x204021, path:"C:\Users\i92segoa"
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x10, path:"C:\Users\i92segoa"
pid:4092, tid:9004, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\Cur
rentVersion\Explorer\KnownFolderSettings"
pid:4092, tid:9004, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\Cur
rentVersion\Explorer\KnownFolderSettings"
pid:4092, tid:9004, tick:0x33D6FF0, lvl:LOG, func:NtCreateFile, status:0xC000003
5, handle:0x0, access:0x100001, iostatus:0x0, information:0xFFFFFFFF, attribs:0x
80, share:0x3, disposition:0x2, options:0x204021, path:"C:\Users\i92segoa\AppDat
a\Local"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x92, handle:0x386, path:"\REGISTRY\USER\S-1-5-21
-2360094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x386, path:"\REGISTRY\USER\S-1-5-21-23
60094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder"
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x10, path:"C:\Users\i92segoa\AppData\Local"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5A0000, zerobits:0x0, commitsize:0x0, offset:0x210000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5B0000
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5B0000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5A0000
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5A0000, zerobits:0x0, commitsize:0x0, offset:0x220000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5B0000
pid:4092, tid:9004, tick:0x33D6FF0, lvl:LOG, func:NtCreateFile, status:0xC000003
5, handle:0x0, access:0x100001, iostatus:0x0, information:0xFFFFFFFF, attribs:0x
80, share:0x3, disposition:0x2, options:0x204021, path:"C:\Users\i92segoa\AppDat
a\Local\Microsoft\Windows\INetCache"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:RecurseRegistryConfig, log:"Du
plicate regkey Wow6432Node will not be added as it is at lower layer."
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5B0000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtUnmapViewOfSection, status:0x

0, address:0x5A0000
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x2016, path:"C:\Users\i92segoa\AppData\Local\Microsoft\Windows\INet
Cache"
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x72AAA000, class:0x0, length:0x1C, resultlength:0x1C
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5A0000, zerobits:0x0, commitsize:0x0, offset:0x270000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"OLEAUT32.dll", handle:0x754E0000
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5B0000
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x754E0000, ordinal:0x2, address:0x754FAB60, image:0x0, cal
ler:0x72A4ABED
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x754E0000, ordinal:0x7, address:0x754F2860, image:0x0, cal
ler:0x72A4ABED
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:NtSetInformationProcess, status
:0x0, class:0xC, length:0x4
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x2016, path:"C:\Users\i92segoa\AppData\Local\Microsoft\Windows\INet
Cache"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:RecurseRegistryConfig, log:"Du
plicate regkey Wow6432Node will not be added as it is at lower layer."
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:NtSetInformationProcess, status
:0x0, class:0xC, length:0x4
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x754E0000, ordinal:0x6, address:0x754FAC10, image:0x0, cal
ler:0x72A4ABED
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5B0000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5A0000
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x3B8, c
lass:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-2602383397-24
63990887-1001", attributes:0x0
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x3
B8
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5A0000, zerobits:0x0, commitsize:0x0, offset:0x220000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5B0000
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:RecurseRegistryConfig, log:"Du
plicate regkey CLSID will not be added as it is at lower layer."
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5B0000, zerobits:0x0, commitsize:0x0, offset:0x270000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5A0000
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:RecurseRegistryConfig, log:"Du
plicate regkey CLSID will not be added as it is at lower layer."
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:RecurseRegistryConfig, log:"Du
plicate regkey Interface will not be added as it is at lower layer."
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5A0000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x100

00, disposition:0x2, type:0x0, protect:0x2, handle:0x78


pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5B0000
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5B0000, zerobits:0x0, commitsize:0x0, offset:0x220000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5A0000
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:NtCreateFile, status:0x0, handl
e:0x3B8, access:0xC0100080, iostatus:0x0, information:0x1, attribs:0x0, share:0x
3, disposition:0x3, options:0x60, path:"C:\Users\i92segoa\AppData\Local\Microsof
t\Windows\INetCache\counters.dat"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5A0000, zerobits:0x0, commitsize:0x0, offset:0x270000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5B0000
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:NtCreateSection, status:0x0, ha
ndle:0x3AC, access:0xF0007, size:0x80, pageattribs:0x4, sectionattribs:0x8000000
, file:0x3B8
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5B0000, zerobits:0x0, commitsize:0x0, offset:0x0, viewsize:0x1000, di
sposition:0x1, type:0x0, protect:0x4, handle:0x3AC, path:"C:\Users\i92segoa\AppD
ata\Local\Microsoft\Windows\INetCache\counters.dat"
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x701C0000
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x38C, access:0x1, path:"\Registry\Machine\Software\Classes\CLSID\{20D04FE0-3AE
A-1069-A2D8-08002B30309D}\ShellFolder"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0xD2, handle:0x38E, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder
"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x38E, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B303
09D}\ShellFolder"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Attributes", class:0x2, length:0x90, resultlength:0x19F6A0, handle:0
x38E, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{20D04FE0-3AEA1069-A2D8-08002B30309D}\ShellFolder"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0xD2, handle:0x38E, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder
"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x20, path:"C:\WINDOWS\SYSTEM32\kernelbase.dll"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x38E, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"api-ms-win-eventing-provider-l1-1-0", module:0x776F0000
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:New_NtQueryInformationToken::<l

ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF


FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x776F0000, name:"EventSetInformation", ordinal:0x0, addres
s:0x77C39FC0, image:0x0, caller:0x7030A15F
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B303
09D}\ShellFolder"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:LdrUnloadDll, status:0x0, handl
e:0x776F0000
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"CallForAttributes", class:0x2, length:0x90, resultlength:0x19F6A0, h
andle:0x38E, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{20D04FE
0-3AEA-1069-A2D8-08002B30309D}\ShellFolder"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0xD2, handle:0x38E, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder
"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x38E, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x3A8, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"MBCSAPIforCrack", class:0x2, length:0x90, resultlength:0x10, handle:
0x3A8, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTW
ARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B303
09D}\ShellFolder"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"RestrictedAttributes", class:0x2, length:0x90, resultlength:0x19F6A0
, handle:0x38E, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{20D0
4FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x3B0, access:0x1, path:"\REGISTRY\MACHINE\Software\Policies\Microsoft\Windows\
CurrentVersion\Internet Settings"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0xD2, handle:0x38E, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder
"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Security_HKLM_only", class:0x2, length:0x90, resultlength:0x29CFBC8,
handle:0x3B0, path:"\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\Curre
ntVersion\Internet Settings"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x38E, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x3
B0
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:New_NtQueryInformationToken::<l

ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF


FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\Software\Policies\Microsoft\In
ternet Explorer\Main\FeatureControl"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B303
09D}\ShellFolder"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"FolderValueFlags", class:0x2, length:0x90, resultlength:0x10, handle:0x38E,
path:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A
2D8-08002B30309D}\ShellFolder"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x3
8E
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x3B0, access:0x1, path:"\REGISTRY\MACHINE\Software\Microsoft\Internet Explorer
\Main\FeatureControl"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x670000, zerobits:0x0, commitsize:0x0, offset:0x210000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5A0000
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{20D04FE0
-3AEA-1069-A2D8-08002B30309D}\ShellFolder"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5A0000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x670000
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\Cur
rentVersion\Explorer\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x3BC, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24639908
87-1001\Software\Microsoft\Internet Explorer\Main\FeatureControl"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_H
TTP_USERNAME_PASSWORD_DISABLE"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x38C, access:0x1, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVe
rsion\Policies\NonEnum"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x3C0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Inter
net Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"{20D04FE0-3AEA-1069-A2D8-08002B30309D}", class:0x2, length:0x90, res
ultlength:0x19EE08, handle:0x38C, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Win
dows\CurrentVersion\Policies\NonEnum"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000

0034, name:"firefox.exe", class:0x2, length:0x90, resultlength:0xAA1199, handle:


0x3C0, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\
Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x3
8C
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"*", class:0x2, length:0x90, resultlength:0xAA1199, handle:0x3C0, pat
h:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\Featu
reControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x3
C0
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x38C, access:0x1, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVe
rsion\Explorer\MyComputer\NameSpace"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies\Microsof
t\Internet Explorer\Main\FeatureControl"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"ValidateRegItems", class:0x2, length:0x90, resultlength:0x19E524, ha
ndle:0x38C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Curre
ntVersion\Explorer\MyComputer\NameSpace"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x3
8C
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001\Software\Policies\Microsoft\Internet Explorer\Main\FeatureCont
rol"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x38C, access:0x1, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVe
rsion\Explorer\MyComputer\NameSpace"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x3C0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Internet Explorer\Main\FeatureControl"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"MonitorRegistry", class:0x2, length:0x90, resultlength:0x19E524, han
dle:0x38C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Curren
tVersion\Explorer\MyComputer\NameSpace"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x3
8C
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x3C8, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Internet Expl
orer\Main\FeatureControl"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x92, handle:0x386, path:"\REGISTRY\USER\S-1-5-21
-2360094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"FEATURE_CLIENTAUTHCERTFILTER", class:0x2, length:0x90, resultlength:
0x0, handle:0x3C0, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246399088
7-1001\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x386, path:"\REGISTRY\USER\S-1-5-21-23
60094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x3
C0
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"FEATURE_CLIENTAUTHCERTFILTER", class:0x2, length:0x90, resultlength:
0x124B600, handle:0x3C8, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\
Internet Explorer\Main\FeatureControl"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x3
C8

pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034


, handle:0x0, access:0x8, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_Classes\Drive\shellex\FolderExtensions"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\RETRY_HEA
DERONLYPOST_ONCONNECTIONRESET"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x38C, access:0x8, path:"\Registry\Machine\Software\Classes\Drive\shellex\Folde
rExtensions"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft
\Internet Explorer\Main\FeatureControl\RETRY_HEADERONLYPOST_ONCONNECTIONRESET"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0x86, handle:0x38E, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\Drive\SHELLEX\FolderExtensions"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_M
IME_HANDLING"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x38E, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\Drive\SHELLEX\FolderExtensions"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x3C8, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Inter
net Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"firefox.exe", class:0x2, length:0x90, resultlength:0xAA1199, handle:
0x3C8, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\
Main\FeatureControl\FEATURE_MIME_HANDLING"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\Drive\SHELLEX\FolderExtensions"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"*", class:0x2, length:0x90, resultlength:0xAA1199, handle:0x3C8, pat
h:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\Featu
reControl\FEATURE_MIME_HANDLING"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x3
C8
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x0, class:0x1, length:0x120, resultlength:0x64, handle:0x38E, path:"\REGISTR
Y\MACHINE\SOFTWARE\Classes\Drive\SHELLEX\FolderExtensions"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_B
YPASS_CACHE_FOR_CREDPOLICY_KB936611"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x92, handle:0x386, path:"\REGISTRY\USER\S-1-5-21
-2360094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft
\Internet Explorer\Main\FeatureControl\FEATURE_BYPASS_CACHE_FOR_CREDPOLICY_KB936
611"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x386, path:"\REGISTRY\USER\S-1-5-21-23
60094602-2602383397-2463990887-1001_Classes"

pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034


, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_I
GNORE_MAPPINGS_FOR_CREDPOLICY"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft
\Internet Explorer\Main\FeatureControl\FEATURE_IGNORE_MAPPINGS_FOR_CREDPOLICY"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-40
9d6c4515e9}"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_I
NCLUDE_PORT_IN_SPN_KB908209"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft
\Internet Explorer\Main\FeatureControl\FEATURE_INCLUDE_PORT_IN_SPN_KB908209"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x3B4, access:0x1, path:"\Registry\Machine\Software\Classes\Drive\shellex\Folde
rExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_B
UFFERBREAKING_818408"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0xD4, handle:0x3B6, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\Drive\SHELLEX\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9
}"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft
\Internet Explorer\Main\FeatureControl\FEATURE_BUFFERBREAKING_818408"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x3B6, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\Drive\SHELLEX\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_S
KIP_POST_RETRY_ON_INTERNETWRITEFILE_KB895954"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft
\Internet Explorer\Main\FeatureControl\FEATURE_SKIP_POST_RETRY_ON_INTERNETWRITEF
ILE_KB895954"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_F
IX_CHUNKED_PROXY_SCRIPT_DOWNLOAD_KB843289"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\Drive\SHELLEX\FolderExtensions\{fbeb8a05-beee-4442-8
04e-409d6c4515e9}"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft
\Internet Explorer\Main\FeatureControl\FEATURE_FIX_CHUNKED_PROXY_SCRIPT_DOWNLOAD
_KB843289"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034

, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24


63990887-1001\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_U
SE_CNAME_FOR_SPN_KB911149"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"DriveMask", class:0x2, length:0x90, resultlength:0x10, handle:0x3B6, path:"\
REGISTRY\MACHINE\SOFTWARE\Classes\Drive\SHELLEX\FolderExtensions\{fbeb8a05-beee4442-804e-409d6c4515e9}"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x3
B6
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft
\Internet Explorer\Main\FeatureControl\FEATURE_USE_CNAME_FOR_SPN_KB911149"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtEnumerateKey, status:0x80000
01A, index:0x1, class:0x1, length:0x120, resultlength:0x64, handle:0x38E, path:"
\REGISTRY\MACHINE\SOFTWARE\Classes\Drive\SHELLEX\FolderExtensions"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_A
LWAYS_USE_DNS_FOR_SPN_KB3022771"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x3
8E
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft
\Internet Explorer\Main\FeatureControl\FEATURE_ALWAYS_USE_DNS_FOR_SPN_KB3022771"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x76B00000
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_P
ERMIT_CACHE_FOR_AUTHENTICATED_FTP_KB910274"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft
\Internet Explorer\Main\FeatureControl\FEATURE_PERMIT_CACHE_FOR_AUTHENTICATED_FT
P_KB910274"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_D
ISABLE_UNICODE_HANDLE_CLOSING_CALLBACK"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x38C, access:0x1, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVe
rsion\Policies\Explorer"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"AllowFileCLSIDJunctions", class:0x2, length:0x90, resultlength:0x19C
DE8, handle:0x38C, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Windows\CurrentVer
sion\Policies\Explorer"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x3C8, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Inter
net Explorer\Main\FeatureControl\FEATURE_DISABLE_UNICODE_HANDLE_CLOSING_CALLBACK
"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x3
8C
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"firefox.exe", class:0x2, length:0x90, resultlength:0xAA1199, handle:
0x3C8, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\
Main\FeatureControl\FEATURE_DISABLE_UNICODE_HANDLE_CLOSING_CALLBACK"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"*", class:0x2, length:0x90, resultlength:0xAA1199, handle:0x3C8, pat
h:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\Featu
reControl\FEATURE_DISABLE_UNICODE_HANDLE_CLOSING_CALLBACK"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034

, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24


63990887-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x3
C8
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_D
ISALLOW_NULL_IN_RESPONSE_HEADERS"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft
\Internet Explorer\Main\FeatureControl\FEATURE_DISALLOW_NULL_IN_RESPONSE_HEADERS
"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x38C, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\Curre
ntVersion\Explorer\KindMap"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_D
IGEST_NO_EXTRAS_IN_URI"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:".exe", class:0x2, length:0x90, resultlength:0x1C, handle:0x38C, path:"\REGIS
TRY\MACHINE\SOFTWARE\MICROSOFT\Windows\CurrentVersion\Explorer\KindMap"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft
\Internet Explorer\Main\FeatureControl\FEATURE_DIGEST_NO_EXTRAS_IN_URI"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x3
8C
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x92, handle:0x386, path:"\REGISTRY\USER\S-1-5-21
-2360094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft
\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_PASSPORT_SESSION_STORE_KB9
48608"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x386, path:"\REGISTRY\USER\S-1-5-21-23
60094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_E
XCLUDE_INVALID_CLIENT_CERT_KB929477"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001_Classes\.exe"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft
\Internet Explorer\Main\FeatureControl\FEATURE_EXCLUDE_INVALID_CLIENT_CERT_KB929
477"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_U
SE_UTF8_FOR_BASIC_AUTH_KB967545"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x38C, access:0x20019, path:"\Registry\Machine\Software\Classes\.exe"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft
\Internet Explorer\Main\FeatureControl\FEATURE_USE_UTF8_FOR_BASIC_AUTH_KB967545"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0x52, handle:0x38E, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\.exe"

pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034


, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_R
ETURN_FAILED_CONNECT_CONTENT_KB942615"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x38E, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\.exe"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft
\Internet Explorer\Main\FeatureControl\FEATURE_RETURN_FAILED_CONNECT_CONTENT_KB9
42615"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_P
RESERVE_SPACES_IN_FILENAMES_KB952730"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft
\Internet Explorer\Main\FeatureControl\FEATURE_PRESERVE_SPACES_IN_FILENAMES_KB95
2730"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\.exe"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"FromCacheTimeout", class:0x2, length:0x90, resultlength:0xA8FDBB, ha
ndle:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\
Software\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Content Type", class:0x2, length:0x90, resultlength:0x3E, handle:0x38E, path
:"\REGISTRY\MACHINE\SOFTWARE\Classes\.exe"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x3
8E
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x717E0000
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x3C0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24639908
87-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"SecureProtocols", class:0x2, length:0x90, resultlength:0x10, handle:0x3C0, p
ath:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Micr
osoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x717E0000
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x3
C0
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x3C8, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x3B4, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{1F486A52-3
CB1-48FD-8F50-B8DC300D9F9D}"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"AppID", class:0x2, length:0x400, resultlength:0x2D006D, handle:0x3B4
, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{1F486A52-3CB1-48FD
-8F50-B8DC300D9F9D}"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x3CC, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Policies"

pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtOpenKey, status:0xC0000034,


handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node
\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\LocalServer32"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x3
B4
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"combase.dll", module:0x74DC0000
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74DC0000, name:"CLSIDFromOle1Class", ordinal:0x0, address
:0x74E92E10, image:0x0, caller:0x74E98AC5
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x670000, zerobits:0x0, commitsize:0x0, offset:0x210000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x3B4, c
lass:0x14, length:0x4, returnlength:0x4
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5A0000
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x3B4, c
lass:0x1A, length:0x4, returnlength:0x4
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x3B4, c
lass:0x1, length:0x64, returnlength:0x24, sid:"S-1-5-21-2360094602-2602383397-24
63990887-1001", attributes:0x0
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5A0000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x670000
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x3D4, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x3C0, access:0x2000000, path:"\Registry\User\S-1-5-21-2360094602-2602383397-2463
990887-1001_Classes"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x3
B4
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x670000, zerobits:0x0, commitsize:0x0, offset:0x220000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5A0000
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5A0000, zerobits:0x0, commitsize:0x0, offset:0x270000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x670000
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x3D8, access:0x20019, path:"\REGISTRY\MACHINE\Software"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtOpenSection, status:0x0, hand
le:0x3B4, access:0x4, path:"\Sessions\1\BaseNamedObjects\Global\__ComCatalogCach
e__"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\Software\Policies\Microsoft\In
ternet Explorer"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x670000, zerobits:0x0, commitsize:0x0, offset:0x0, viewsize:0x1000, di
sposition:0x1, type:0x0, protect:0x2, handle:0x3B4, path:"\BaseNamedObjects\__Co
mCatalogCache__"

pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:New_NtQueryInformationToken::<l


ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x3DC, c
lass:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x3E0, access:0x1, path:"\REGISTRY\MACHINE\Software\Policies\Microsoft\Windows\
CurrentVersion\Internet Settings"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x3
DC
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryKey, status:0x0, class:0
x4, length:0xB0, resultlength:0x28, handle:0x3E0, path:"\REGISTRY\MACHINE\SOFTWA
RE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x3
E0
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x3DC, access:0x20119, path:"\REGISTRY\MACHINE\Software\Microsoft\COM3"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Com+Enabled", class:0x2, length:0x90, resultlength:0x10, handle:0x3DC, path:
"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\COM3"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x3
DC
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x3E4, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24639908
87-1001\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryKey, status:0x0, class:0
x4, length:0xB0, resultlength:0x28, handle:0x3E4, path:"\REGISTRY\USER\S-1-5-212360094602-2602383397-2463990887-1001\SOFTWARE\Policies\Microsoft\Windows\Curren
tVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x3
E4
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtOpenSection, status:0x0, hand
le:0x3DC, access:0xF, path:"\KnownDlls32\clbcatq.dll"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x3E8, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24639908
87-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x76A70000, zerobits:0x0, commitsize:0x0, viewsize:0x84000, disposition
:0x1, type:0x800000, protect:0x4, handle:0x3DC, path:"\KnownDlls32\clbcatq.dll"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"CertificateRevocation", class:0x2, length:0x90, resultlength:0x10, handle:0x
3E8, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWAR
E\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x3
E8
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DisableKeepAlive", class:0x2, length:0x90, resultlength:0x80, handle
:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\Soft
ware\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x3
DC
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"IdnEnabled", class:0x2, length:0x90, resultlength:0x29CF4AC, handle:
0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\Softw
are\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"PreConnectLimit", class:0x2, length:0x90, resultlength:0x29CF4AC, ha
ndle:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\
Software\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"PreResolveLimit", class:0x2, length:0x90, resultlength:0x29CF4AC, ha
ndle:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\

Software\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"CacheMode", class:0x2, length:0x90, resultlength:0x29CF4AC, handle:0
x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\Softwa
re\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtOpenEvent, status:0x0, handle
:0x3E0, access:0x100001, path:"\KernelObjects\MaximumCommitCondition"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x3E4, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies\Microsoft\Wind
ows\CurrentVersion\Internet Settings"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x74DC0000
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"EnableHttp1_1", class:0x2, length:0x90, resultlength:0x10, handle:0x
3E4, path:"\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\
Internet Settings"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x76A70000
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"EnableHttp1_1", class:0x2, length:0x90, resultlength:0x10, handle:0x
3A8, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWAR
E\Policies\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"EnableHttp1_1", class:0x2, length:0x90, resultlength:0x10, handle:0x370, pat
h:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\Software\Micros
oft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"ProxyHttp1.1", class:0x2, length:0x90, resultlength:0x10, handle:0x3
E4, path:"\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\I
nternet Settings"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\Microsoft\Ole\App
Compat\DisableClsidFreeActivatableClasses"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"ProxyHttp1.1", class:0x2, length:0x90, resultlength:0x10, handle:0x3
A8, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE
\Policies\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ProxyHttp1.1", class:0x2, length:0x90, resultlength:0x10, handle:0x370, path
:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\Software\Microso
ft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"EnableNegotiate", class:0x2, length:0x90, resultlength:0x10, handle:0x370, p
ath:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\Software\Micr
osoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DisableBasicOverClearChannel", class:0x2, length:0x90, resultlength:
0x10, handle:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24639908
87-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtOpenSection, status:0x0, hand
le:0x3E8, access:0x4, path:"\Sessions\1\BaseNamedObjects\Global\__ComCatalogCach
e__"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"EnableAutoProxyResultCache", class:0x2, length:0x90, resultlength:0x
10, handle:0x3A8, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887
-1001\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x6D0000, zerobits:0x0, commitsize:0x0, offset:0x0, viewsize:0x1000, di
sposition:0x1, type:0x0, protect:0x2, handle:0x3E8, path:"\BaseNamedObjects\__Co
mCatalogCache__"

pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000


0034, name:"DisplayScriptDownloadFailureUI", class:0x2, length:0x90, resultlengt
h:0x10, handle:0x3A8, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246399
0887-1001\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"MBCSServername", class:0x2, length:0x90, resultlength:0x10, handle:0
x3A8, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWA
RE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"UTF8ServerNameRes", class:0x2, length:0x90, resultlength:0x10, handl
e:0x3A8, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOF
TWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DisableReadRange", class:0x2, length:0x90, resultlength:0x10, handle
:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\Soft
ware\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"SocketSendBufferLength", class:0x2, length:0x90, resultlength:0x29CF
4AC, handle:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246399088
7-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"SocketReceiveBufferLength", class:0x2, length:0x90, resultlength:0x2
9CF4AC, handle:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246399
0887-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"KeepAliveTimeout", class:0x2, length:0x90, resultlength:0x29CF4AC, h
andle:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001
\Software\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtCreateFile, status:0x0, handl
e:0x3EC, access:0x80100080, iostatus:0x0, information:0x1, attribs:0x0, share:0x
1, disposition:0x1, options:0x60, path:"C:\WINDOWS\Registration\R00000000000d.cl
b"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"MaxHttpRedirects", class:0x2, length:0x90, resultlength:0x29CF4AC, h
andle:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001
\Software\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryInformationFile, status:
0x0, iostatus:0x0, information:0x18, length:0x18, class:0x5, handle:0x3EC, path:
"C:\WINDOWS\Registration\R00000000000d.clb"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtSetInformationFile, status:0x
0, iostatus:0x0, information:0x0, length:0x8, class:0xE, handle:0x3EC, path:"C:\
WINDOWS\Registration\R00000000000d.clb"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"MaxConnectionsPerServer", class:0x2, length:0x90, resultlength:0x29C
F4AC, handle:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24639908
87-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtCreateSection, status:0x0, ha
ndle:0x3F0, access:0xF0005, pageattribs:0x2, sectionattribs:0x8000000, file:0x3E
C
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x6E0000, zerobits:0x0, commitsize:0x0, offset:0x0, viewsize:0x6000, di
sposition:0x1, type:0x0, protect:0x2, handle:0x3F0, path:"C:\WINDOWS\Registratio
n\R00000000000d.clb"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x3F4, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\Curre
ntVersion\Internet Settings"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtSetInformationFile, status:0x
0, iostatus:0x0, information:0x0, length:0x8, class:0xE, handle:0x3EC, path:"C:\
WINDOWS\Registration\R00000000000d.clb"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000

0034, name:"MaxConnectionsPerServer", class:0x2, length:0x90, resultlength:0x10,


handle:0x3F4, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Cu
rrentVersion\Internet Settings"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtSetInformationFile, status:0x
0, iostatus:0x0, information:0x0, length:0x8, class:0xE, handle:0x3EC, path:"C:\
WINDOWS\Registration\R00000000000d.clb"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtSetInformationFile, status:0x
0, iostatus:0x0, information:0x0, length:0x8, class:0xE, handle:0x3EC, path:"C:\
WINDOWS\Registration\R00000000000d.clb"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"MaxConnectionsPer1_0Server", class:0x2, length:0x90, resultlength:0x
10, handle:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887
-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"MaxConnectionsPer1_0Server", class:0x2, length:0x90, resultlength:0x
10, handle:0x3F4, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows
\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"MaxConnectionsPerProxy", class:0x2, length:0x90, resultlength:0x10,
handle:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-100
1\Software\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"MaxConnectionsPerProxy", class:0x2, length:0x90, resultlength:0x10,
handle:0x3F4, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Cur
rentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"ServerInfoTimeout", class:0x2, length:0x90, resultlength:0x10, handl
e:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\Sof
tware\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"ConnectTimeOut", class:0x2, length:0x90, resultlength:0x10, handle:0
x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\Softwa
re\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"ConnectTimeOut", class:0x2, length:0x90, resultlength:0x10, handle:0
x3F4, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVers
ion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"ConnectRetries", class:0x2, length:0x90, resultlength:0x10, handle:0
x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\Softwa
re\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"ConnectRetries", class:0x2, length:0x90, resultlength:0x10, handle:0
x3F4, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVers
ion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"SendTimeOut", class:0x2, length:0x90, resultlength:0x10, handle:0x37
0, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\Software\
Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"SendTimeOut", class:0x2, length:0x90, resultlength:0x10, handle:0x3F
4, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion
\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"ReceiveTimeOut", class:0x2, length:0x90, resultlength:0x10, handle:0
x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\Softwa
re\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"ReceiveTimeOut", class:0x2, length:0x90, resultlength:0x10, handle:0
x3F4, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVers

ion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DisableNTLMPreAuth", class:0x2, length:0x90, resultlength:0x7834A0,
handle:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-100
1\Software\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"CertCacheNoValidate", class:0x2, length:0x90, resultlength:0x7834A0,
handle:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-10
01\Software\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_D
ISABLE_NOTIFY_UNVERIFIED_SPN_KB2385266"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft
\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_NOTIFY_UNVERIFIED_SPN_KB2
385266"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_C
OMPAT_USE_CONNECTION_BASED_NEGOTIATE_AUTH_KB2151543"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft
\Internet Explorer\Main\FeatureControl\FEATURE_COMPAT_USE_CONNECTION_BASED_NEGOT
IATE_AUTH_KB2151543"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"HttpDefaultExpiryTimeSecs", class:0x2, length:0x90, resultlength:0x2
9CFC0C, handle:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246399
0887-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"FtpDefaultExpiryTimeSecs", class:0x2, length:0x90, resultlength:0x29
CFC0C, handle:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990
887-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x3FC, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24639908
87-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"DisableCachingOfSSLPages", class:0x2, length:0x90, resultlength:0x10, handle
:0x3FC, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFT
WARE\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x3
FC
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"LeashLegacyCookies", class:0x2, length:0x90, resultlength:0x80, hand
le:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\So
ftware\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DialupUseLanSettings", class:0x2, length:0x90, resultlength:0x80, ha
ndle:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\
Software\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DialupUseLanSettings", class:0x2, length:0x90, resultlength:0x80, ha
ndle:0x3F4, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Curre
ntVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"SendExtraCRLF", class:0x2, length:0x90, resultlength:0x80, handle:0x
370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\Softwar
e\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"BypassHTTPNoCacheCheck", class:0x2, length:0x90, resultlength:0x80,

handle:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-100
1\Software\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"BypassHTTPNoCacheCheck", class:0x2, length:0x90, resultlength:0x80,
handle:0x3F4, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Cur
rentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"BypassSSLNoCacheCheck", class:0x2, length:0x90, resultlength:0x80, h
andle:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001
\Software\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"BypassSSLNoCacheCheck", class:0x2, length:0x90, resultlength:0x80, h
andle:0x3F4, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Curr
entVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"EnableHttpTrace", class:0x2, length:0x90, resultlength:0x80, handle:
0x3F4, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVer
sion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"NoCheckAutodialOverRide", class:0x2, length:0x90, resultlength:0x80,
handle:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-10
01\Software\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"NoCheckAutodialOverRide", class:0x2, length:0x90, resultlength:0x80,
handle:0x3F4, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Cu
rrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_S
CH_SEND_AUX_RECORD_KB_2618444"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft
\Internet Explorer\Main\FeatureControl\FEATURE_SCH_SEND_AUX_RECORD_KB_2618444"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DontUseDNSLoadBalancing", class:0x2, length:0x90, resultlength:0xEE,
handle:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-10
01\Software\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DontUseDNSLoadBalancing", class:0x2, length:0x90, resultlength:0xEE,
handle:0x3F4, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Cu
rrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"ShareCredsWithWinHttp", class:0x2, length:0x90, resultlength:0xEE, h
andle:0x3F4, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Curr
entVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"MimeExclusionListForCache", class:0x2, length:0x90, resultlength:0x6
80000, handle:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990
887-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"MimeExclusionListForCache", class:0x2, length:0x90, resultlength:0xF
FFFFFB6, handle:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24639
90887-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"HeaderExclusionListForCache", class:0x2, length:0x90, resultlength:0
x728EE23B, handle:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246
3990887-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_E

NABLE_TOKEN_BINDING"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft
\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_TOKEN_BINDING"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DnsCacheEnabled", class:0x2, length:0x90, resultlength:0x41004D, han
dle:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\S
oftware\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DnsCacheEntries", class:0x2, length:0x90, resultlength:0x29CF4E8, ha
ndle:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\
Software\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DnsCacheTimeout", class:0x2, length:0x90, resultlength:0x29CF4E8, ha
ndle:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\
Software\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"WarnOnPost", class:0x2, length:0x90, resultlength:0x29CF49C, handle:
0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\Softw
are\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"WarnAlwaysOnPost", class:0x2, length:0x90, resultlength:0x29CF49C, h
andle:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001
\Software\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x92, handle:0x3C2, path:"\Registry\User\S-1-5-21
-2360094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"WarnOnZoneCrossing", class:0x2, length:0x90, resultlength:0x10, handle:0x370
, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\Software\M
icrosoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x3C2, path:"\Registry\User\S-1-5-21-23
60094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"WarnOnBadCertRecving", class:0x2, length:0x90, resultlength:0x10, ha
ndle:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\
Software\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"WarnOnPostRedirect", class:0x2, length:0x90, resultlength:0x10, hand
le:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\So
ftware\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\Registry\User\S-1-5-21-2360094602-260238339
7-2463990887-1001_Classes\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"AlwaysDrainOnRedirect", class:0x2, length:0x90, resultlength:0x10, h
andle:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001
\Software\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"WarnOnHTTPSToHTTPRedirect", class:0x2, length:0x90, resultlength:0x1
0, handle:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24639908871001\Software\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x3F8, access:0x20019, path:"\Registry\Machine\Software\Classes\CLSID\{1F486A52
-3CB1-48FD-8F50-B8DC300D9F9D}"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"TcpAutotuning", class:0x2, length:0x90, resultlength:0x29CF500, hand
le:0x3F4, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Current
Version\Internet Settings"

pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryKey, status:0x0, class:0


x3, length:0x180, resultlength:0xBA, handle:0x3FA, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x701C0000
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x3FA, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x38C, c
lass:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x3
8C
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_Classes\WOW6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\T
reatAs"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000022
, handle:0x0, access:0xF003F, path:"\REGISTRY\MACHINE\System\CurrentControlSet\S
ervices\WinSock2\Parameters"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\C
LSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\TreatAs"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x204, resultlength:0xBA, handle:0x3FA, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x38C, access:0x20019, path:"\REGISTRY\MACHINE\System\CurrentControlSet\Service
s\WinSock2\Parameters"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"WinSock_Registry_Version", class:0x2, length:0x90, resultlength:0x14, handle
:0x38C, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameter
s"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0xBA, handle:0x3FA, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"WinSock_Registry_Version", class:0x2, length:0x90, resultlength:0x14, handle
:0x38C, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameter
s"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x3FA, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x3A4, access:0x20019, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Wi
nSock2\Parameters\AppId_Catalog"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:GetCommandLineW, ret:0x124EAA0,
gle:0x0, cmdline:"\"C:\Program Files (x86)\Mozilla Firefox\firefox.exe\""
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Servi
ces\WinSock2\Parameters\AppId_Catalog\04CC76E4"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x3

A4
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\WOW6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9
F9D}"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"NameSpace_Callout", class:0x2, length:0x90, resultlength:0x52, handle:0x38C,
path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"NameSpace_Callout", class:0x2, length:0x90, resultlength:0x52, handle:0x38C,
path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"", class:0x2, length:0x90, resultlength:0x3C, handle:0x3FA, path:"\REGISTRY\
MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D
}"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x3C4, access:0x2000000, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\
WinSock2\Parameters\Protocol_Catalog9"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0xBA, handle:0x3FA, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Serial_Access_Num", class:0x2, length:0x90, resultlength:0x10, handle:0x3C4,
path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Proto
col_Catalog9"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x3FA, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtNotifyChangeKey, status:0x103
, event:0x3A4, iostatus:0x103, information:0x0, filter:0x1, watch:0x0, length:0x
0, async:0x1, handle:0x3C4, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Service
s\WinSock2\Parameters\Protocol_Catalog9"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Serial_Access_Num", class:0x2, length:0x90, resultlength:0x10, handle:0x3C4,
path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Proto
col_Catalog9"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Servi
ces\WinSock2\Parameters\Protocol_Catalog9\00000009"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\WOW6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9
F9D}"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Next_Catalog_Entry_ID", class:0x2, length:0x90, resultlength:0x10, handle:0x
3C4, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\P
rotocol_Catalog9"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Num_Catalog_Entries", class:0x2, length:0x90, resultlength:0x10, handle:0x3C
4, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Pro
tocol_Catalog9"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"", class:0x2, length:0x90, resultlength:0x3C, handle:0x3FA, path:"\REGISTRY\
MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D
}"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle

:0x3FC, access:0x2000000, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\


WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0xBA, handle:0x3FA, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x404, access:0x20019, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Wi
nSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0x8000
0005, name:"PackedCatalogItem", class:0x2, length:0x90, resultlength:0x384, hand
le:0x404, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Paramet
ers\Protocol_Catalog9\Catalog_Entries\000000000001"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x3FA, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"PackedCatalogItem", class:0x2, length:0x384, resultlength:0x384, handle:0x40
4, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Pro
tocol_Catalog9\Catalog_Entries\000000000001"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x4
04
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x404, access:0x20019, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Wi
nSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0x8000
0005, name:"PackedCatalogItem", class:0x2, length:0x90, resultlength:0x384, hand
le:0x404, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Paramet
ers\Protocol_Catalog9\Catalog_Entries\000000000002"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001_Classes\WOW6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9
D}\InprocServer32"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"PackedCatalogItem", class:0x2, length:0x384, resultlength:0x384, handle:0x40
4, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Pro
tocol_Catalog9\Catalog_Entries\000000000002"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x4
04
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x404, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLS
ID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\InprocServer32"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x40C, access:0x20019, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Wi
nSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0xD8, handle:0x406, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\InProcServe
r32"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0x8000
0005, name:"PackedCatalogItem", class:0x2, length:0x90, resultlength:0x384, hand
le:0x40C, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Paramet
ers\Protocol_Catalog9\Catalog_Entries\000000000003"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x406, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\InProcServer32
"

pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na


me:"PackedCatalogItem", class:0x2, length:0x384, resultlength:0x384, handle:0x40
C, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Pro
tocol_Catalog9\Catalog_Entries\000000000003"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x4
0C
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x40C, access:0x20019, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Wi
nSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\WOW6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9
F9D}\InProcServer32"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0x8000
0005, name:"PackedCatalogItem", class:0x2, length:0x90, resultlength:0x384, hand
le:0x40C, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Paramet
ers\Protocol_Catalog9\Catalog_Entries\000000000004"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"InprocServer32", class:0x2, length:0x90, resultlength:0x0, handle:0x
406, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{1F486A52-3CB1-4
8FD-8F50-B8DC300D9F9D}\InProcServer32"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"PackedCatalogItem", class:0x2, length:0x384, resultlength:0x384, handle:0x40
C, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Pro
tocol_Catalog9\Catalog_Entries\000000000004"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0xD8, handle:0x406, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\InProcServe
r32"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x4
0C
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x406, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\InProcServer32
"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x40C, access:0x20019, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Wi
nSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0x8000
0005, name:"PackedCatalogItem", class:0x2, length:0x90, resultlength:0x384, hand
le:0x40C, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Paramet
ers\Protocol_Catalog9\Catalog_Entries\000000000005"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\WOW6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9
F9D}\InProcServer32"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"PackedCatalogItem", class:0x2, length:0x384, resultlength:0x384, handle:0x40
C, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Pro
tocol_Catalog9\Catalog_Entries\000000000005"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"", class:0x2, length:0x90, resultlength:0x50, handle:0x406, path:"\REGISTRY\

MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D
}\InProcServer32"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x4
0C
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0xD8, handle:0x406, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\InProcServe
r32"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x40C, access:0x20019, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Wi
nSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x406, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\InProcServer32
"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0x8000
0005, name:"PackedCatalogItem", class:0x2, length:0x90, resultlength:0x384, hand
le:0x40C, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Paramet
ers\Protocol_Catalog9\Catalog_Entries\000000000006"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"PackedCatalogItem", class:0x2, length:0x384, resultlength:0x384, handle:0x40
C, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Pro
tocol_Catalog9\Catalog_Entries\000000000006"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x4
0C
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\WOW6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9
F9D}\InProcServer32"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"", class:0x2, length:0x90, resultlength:0x50, handle:0x406, path:"\REGISTRY\
MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D
}\InProcServer32"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x40C, access:0x20019, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Wi
nSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0xD8, handle:0x406, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\InProcServe
r32"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0x8000
0005, name:"PackedCatalogItem", class:0x2, length:0x90, resultlength:0x384, hand
le:0x40C, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Paramet
ers\Protocol_Catalog9\Catalog_Entries\000000000007"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x406, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\InProcServer32
"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"PackedCatalogItem", class:0x2, length:0x384, resultlength:0x384, handle:0x40
C, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Pro
tocol_Catalog9\Catalog_Entries\000000000007"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0

pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x4


0C
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x40C, access:0x20019, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Wi
nSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\WOW6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9
F9D}\InProcServer32"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0x8000
0005, name:"PackedCatalogItem", class:0x2, length:0x90, resultlength:0x384, hand
le:0x40C, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Paramet
ers\Protocol_Catalog9\Catalog_Entries\000000000008"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"", class:0x2, length:0x90, resultlength:0x50, handle:0x406, path:"\REGISTRY\
MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D
}\InProcServer32"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"PackedCatalogItem", class:0x2, length:0x384, resultlength:0x384, handle:0x40
C, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Pro
tocol_Catalog9\Catalog_Entries\000000000008"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x4
0C
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0xD8, handle:0x406, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\InProcServe
r32"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x40C, access:0x20019, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Wi
nSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0x8000
0005, name:"PackedCatalogItem", class:0x2, length:0x90, resultlength:0x384, hand
le:0x40C, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Paramet
ers\Protocol_Catalog9\Catalog_Entries\000000000009"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x406, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\InProcServer32
"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"PackedCatalogItem", class:0x2, length:0x384, resultlength:0x384, handle:0x40
C, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Pro
tocol_Catalog9\Catalog_Entries\000000000009"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x4
0C
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\WOW6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9
F9D}\InProcServer32"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x40C, access:0x20019, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Wi
nSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ThreadingModel", class:0x2, length:0x90, resultlength:0x16, handle:0x406, pa
th:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{1F486A52-3CB1-48FD-8F5
0-B8DC300D9F9D}\InProcServer32"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0x8000

0005, name:"PackedCatalogItem", class:0x2, length:0x90, resultlength:0x384, hand


le:0x40C, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Paramet
ers\Protocol_Catalog9\Catalog_Entries\000000000010"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x4
06
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"PackedCatalogItem", class:0x2, length:0x384, resultlength:0x384, handle:0x40
C, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Pro
tocol_Catalog9\Catalog_Entries\000000000010"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0xBA, handle:0x3FA, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x4
0C
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x3FA, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x40C, access:0x20019, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Wi
nSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0x8000
0005, name:"PackedCatalogItem", class:0x2, length:0x90, resultlength:0x384, hand
le:0x40C, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Paramet
ers\Protocol_Catalog9\Catalog_Entries\000000000011"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"PackedCatalogItem", class:0x2, length:0x384, resultlength:0x384, handle:0x40
C, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Pro
tocol_Catalog9\Catalog_Entries\000000000011"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x4
0C
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_Classes\WOW6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\I
nprocHandler32"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x3
FC
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x3FC, c
lass:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x3
FC
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\C
LSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\InprocHandler32"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x40C, access:0x2000000, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\
WinSock2\Parameters\NameSpace_Catalog5"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0xBA, handle:0x3FA, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Serial_Access_Num", class:0x2, length:0x90, resultlength:0x10, handle:0x40C,
path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameS
pace_Catalog5"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x3FA, path:"\REGISTRY\MACHINE\SOFTWARE

\Classes\WOW6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtNotifyChangeKey, status:0x103
, event:0x3FC, iostatus:0x103, information:0x0, filter:0x1, watch:0x0, length:0x
0, async:0x1, handle:0x40C, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Service
s\WinSock2\Parameters\NameSpace_Catalog5"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Serial_Access_Num", class:0x2, length:0x90, resultlength:0x10, handle:0x40C,
path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameS
pace_Catalog5"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Servi
ces\WinSock2\Parameters\NameSpace_Catalog5\00000014"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Num_Catalog_Entries", class:0x2, length:0x90, resultlength:0x10, handle:0x40
C, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Nam
eSpace_Catalog5"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_Classes\WOW6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\I
nprocHandler"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x414, access:0x2000000, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\
WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\C
LSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\InprocHandler"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x418, access:0x20019, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Wi
nSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x3
FA
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"LibraryPath", class:0x2, length:0x90, resultlength:0x50, handle:0x418, path:
"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_C
atalog5\Catalog_Entries\000000000001"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"LibraryPath", class:0x2, length:0x90, resultlength:0x50, handle:0x418, path:
"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_C
atalog5\Catalog_Entries\000000000001"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"DisplayString", class:0x2, length:0x90, resultlength:0x5E, handle:0x418, pat
h:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace
_Catalog5\Catalog_Entries\000000000001"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"DisplayString", class:0x2, length:0x90, resultlength:0x5E, handle:0x418, pat
h:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace
_Catalog5\Catalog_Entries\000000000001"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x3F8, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\OLE"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"DisplayString", class:0x2, length:0x90, resultlength:0x5E, handle:0x418, pat
h:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace
_Catalog5\Catalog_Entries\000000000001"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"DisplayString", class:0x2, length:0x90, resultlength:0x5E, handle:0x418, pat
h:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace

_Catalog5\Catalog_Entries\000000000001"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"MaxSxSHashCount", class:0x2, length:0x90, resultlength:0x0, handle:0
x3F8, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\OLE"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ProviderId", class:0x2, length:0x90, resultlength:0x1C, handle:0x418, path:"
\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_Ca
talog5\Catalog_Entries\000000000001"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x3
F8
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"AddressFamily", class:0x2, length:0x90, resultlength:0x201CC, handle
:0x418, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameter
s\NameSpace_Catalog5\Catalog_Entries\000000000001"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"SupportedNameSpace", class:0x2, length:0x90, resultlength:0x10, handle:0x418
, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Name
Space_Catalog5\Catalog_Entries\000000000001"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Enabled", class:0x2, length:0x90, resultlength:0x10, handle:0x418, path:"\RE
GISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_Catal
og5\Catalog_Entries\000000000001"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Version", class:0x2, length:0x90, resultlength:0x10, handle:0x418, path:"\RE
GISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_Catal
og5\Catalog_Entries\000000000001"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x3F8, c
lass:0x14, length:0x4, returnlength:0x4
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"StoresServiceClassInfo", class:0x2, length:0x90, resultlength:0x10, handle:0
x418, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\
NameSpace_Catalog5\Catalog_Entries\000000000001"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x3F8, c
lass:0x1A, length:0x4, returnlength:0x4
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ProviderInfo", class:0x2, length:0x90, resultlength:0xC, handle:0x418, path:
"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_C
atalog5\Catalog_Entries\000000000001"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x3F8, c
lass:0x1, length:0x64, returnlength:0x24, sid:"S-1-5-21-2360094602-2602383397-24
63990887-1001", attributes:0x0
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ProviderInfo", class:0x2, length:0x90, resultlength:0xC, handle:0x418, path:
"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_C
atalog5\Catalog_Entries\000000000001"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x4
18
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x418, access:0x20019, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Wi
nSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"LibraryPath", class:0x2, length:0x90, resultlength:0x50, handle:0x418, path:
"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_C
atalog5\Catalog_Entries\000000000002"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"LibraryPath", class:0x2, length:0x90, resultlength:0x50, handle:0x418, path:
"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_C

atalog5\Catalog_Entries\000000000002"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"DisplayString", class:0x2, length:0x90, resultlength:0x5E, handle:0x418, pat
h:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace
_Catalog5\Catalog_Entries\000000000002"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x420, access:0x2000000, path:"\Registry\User\S-1-5-21-2360094602-2602383397-2463
990887-1001_Classes"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"DisplayString", class:0x2, length:0x90, resultlength:0x5E, handle:0x418, pat
h:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace
_Catalog5\Catalog_Entries\000000000002"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x3
F8
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"DisplayString", class:0x2, length:0x90, resultlength:0x5E, handle:0x418, pat
h:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace
_Catalog5\Catalog_Entries\000000000002"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"DisplayString", class:0x2, length:0x90, resultlength:0x5E, handle:0x418, pat
h:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace
_Catalog5\Catalog_Entries\000000000002"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ProviderId", class:0x2, length:0x90, resultlength:0x1C, handle:0x418, path:"
\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_Ca
talog5\Catalog_Entries\000000000002"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"AddressFamily", class:0x2, length:0x90, resultlength:0x201CC, handle
:0x418, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameter
s\NameSpace_Catalog5\Catalog_Entries\000000000002"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"SupportedNameSpace", class:0x2, length:0x90, resultlength:0x10, handle:0x418
, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Name
Space_Catalog5\Catalog_Entries\000000000002"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Enabled", class:0x2, length:0x90, resultlength:0x10, handle:0x418, path:"\RE
GISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_Catal
og5\Catalog_Entries\000000000002"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Version", class:0x2, length:0x90, resultlength:0x10, handle:0x418, path:"\RE
GISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_Catal
og5\Catalog_Entries\000000000002"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"StoresServiceClassInfo", class:0x2, length:0x90, resultlength:0x10, handle:0
x418, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\
NameSpace_Catalog5\Catalog_Entries\000000000002"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ProviderInfo", class:0x2, length:0x90, resultlength:0xC, handle:0x418, path:
"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_C
atalog5\Catalog_Entries\000000000002"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ProviderInfo", class:0x2, length:0x90, resultlength:0xC, handle:0x418, path:
"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_C
atalog5\Catalog_Entries\000000000002"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
18
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x418, access:0x20019, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Wi
nSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na

me:"LibraryPath", class:0x2, length:0x90, resultlength:0x50, handle:0x418, path:


"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_C
atalog5\Catalog_Entries\000000000003"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"LibraryPath", class:0x2, length:0x90, resultlength:0x50, handle:0x418, path:
"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_C
atalog5\Catalog_Entries\000000000003"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"DisplayString", class:0x2, length:0x90, resultlength:0x5E, handle:0x418, pat
h:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace
_Catalog5\Catalog_Entries\000000000003"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"DisplayString", class:0x2, length:0x90, resultlength:0x5E, handle:0x418, pat
h:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace
_Catalog5\Catalog_Entries\000000000003"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"DisplayString", class:0x2, length:0x90, resultlength:0x5E, handle:0x418, pat
h:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace
_Catalog5\Catalog_Entries\000000000003"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"DisplayString", class:0x2, length:0x90, resultlength:0x5E, handle:0x418, pat
h:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace
_Catalog5\Catalog_Entries\000000000003"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ProviderId", class:0x2, length:0x90, resultlength:0x1C, handle:0x418, path:"
\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_Ca
talog5\Catalog_Entries\000000000003"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"AddressFamily", class:0x2, length:0x90, resultlength:0x201CC, handle
:0x418, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameter
s\NameSpace_Catalog5\Catalog_Entries\000000000003"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"SupportedNameSpace", class:0x2, length:0x90, resultlength:0x10, handle:0x418
, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Name
Space_Catalog5\Catalog_Entries\000000000003"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Enabled", class:0x2, length:0x90, resultlength:0x10, handle:0x418, path:"\RE
GISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_Catal
og5\Catalog_Entries\000000000003"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Version", class:0x2, length:0x90, resultlength:0x10, handle:0x418, path:"\RE
GISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_Catal
og5\Catalog_Entries\000000000003"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"StoresServiceClassInfo", class:0x2, length:0x90, resultlength:0x10, handle:0
x418, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\
NameSpace_Catalog5\Catalog_Entries\000000000003"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ProviderInfo", class:0x2, length:0x90, resultlength:0xC, handle:0x418, path:
"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_C
atalog5\Catalog_Entries\000000000003"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ProviderInfo", class:0x2, length:0x90, resultlength:0xC, handle:0x418, path:
"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_C
atalog5\Catalog_Entries\000000000003"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
18
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x418, access:0x20019, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Wi
nSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004"

pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na


me:"LibraryPath", class:0x2, length:0x90, resultlength:0x4E, handle:0x418, path:
"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_C
atalog5\Catalog_Entries\000000000004"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"LibraryPath", class:0x2, length:0x90, resultlength:0x4E, handle:0x418, path:
"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_C
atalog5\Catalog_Entries\000000000004"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"DisplayString", class:0x2, length:0x90, resultlength:0x5C, handle:0x418, pat
h:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace
_Catalog5\Catalog_Entries\000000000004"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"DisplayString", class:0x2, length:0x90, resultlength:0x5C, handle:0x418, pat
h:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace
_Catalog5\Catalog_Entries\000000000004"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"DisplayString", class:0x2, length:0x90, resultlength:0x5C, handle:0x418, pat
h:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace
_Catalog5\Catalog_Entries\000000000004"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"DisplayString", class:0x2, length:0x90, resultlength:0x5C, handle:0x418, pat
h:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace
_Catalog5\Catalog_Entries\000000000004"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ProviderId", class:0x2, length:0x90, resultlength:0x1C, handle:0x418, path:"
\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_Ca
talog5\Catalog_Entries\000000000004"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"AddressFamily", class:0x2, length:0x90, resultlength:0x201CC, handle
:0x418, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameter
s\NameSpace_Catalog5\Catalog_Entries\000000000004"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"SupportedNameSpace", class:0x2, length:0x90, resultlength:0x10, handle:0x418
, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Name
Space_Catalog5\Catalog_Entries\000000000004"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Enabled", class:0x2, length:0x90, resultlength:0x10, handle:0x418, path:"\RE
GISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_Catal
og5\Catalog_Entries\000000000004"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Version", class:0x2, length:0x90, resultlength:0x10, handle:0x418, path:"\RE
GISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_Catal
og5\Catalog_Entries\000000000004"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"StoresServiceClassInfo", class:0x2, length:0x90, resultlength:0x10, handle:0
x418, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\
NameSpace_Catalog5\Catalog_Entries\000000000004"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ProviderInfo", class:0x2, length:0x90, resultlength:0xC, handle:0x418, path:
"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_C
atalog5\Catalog_Entries\000000000004"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ProviderInfo", class:0x2, length:0x90, resultlength:0xC, handle:0x418, path:
"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_C
atalog5\Catalog_Entries\000000000004"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
18
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x418, access:0x20019, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Wi

nSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"LibraryPath", class:0x2, length:0x90, resultlength:0x50, handle:0x418, path:
"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_C
atalog5\Catalog_Entries\000000000005"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x92, handle:0x422, path:"\Registry\User\S-1-5-21
-2360094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"LibraryPath", class:0x2, length:0x90, resultlength:0x50, handle:0x418, path:
"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_C
atalog5\Catalog_Entries\000000000005"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x422, path:"\Registry\User\S-1-5-21-23
60094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"DisplayString", class:0x2, length:0x90, resultlength:0x62, handle:0x418, pat
h:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace
_Catalog5\Catalog_Entries\000000000005"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"DisplayString", class:0x2, length:0x90, resultlength:0x62, handle:0x418, pat
h:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace
_Catalog5\Catalog_Entries\000000000005"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\Registry\User\S-1-5-21-2360094602-260238339
7-2463990887-1001_Classes\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"DisplayString", class:0x2, length:0x90, resultlength:0x62, handle:0x418, pat
h:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace
_Catalog5\Catalog_Entries\000000000005"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"DisplayString", class:0x2, length:0x90, resultlength:0x62, handle:0x418, pat
h:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace
_Catalog5\Catalog_Entries\000000000005"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x3F8, access:0x20019, path:"\Registry\Machine\Software\Classes\CLSID\{1F486A52
-3CB1-48FD-8F50-B8DC300D9F9D}"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ProviderId", class:0x2, length:0x90, resultlength:0x1C, handle:0x418, path:"
\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_Ca
talog5\Catalog_Entries\000000000005"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0xBA, handle:0x3FA, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x3FA, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"AddressFamily", class:0x2, length:0x90, resultlength:0x201CC, handle
:0x418, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameter
s\NameSpace_Catalog5\Catalog_Entries\000000000005"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"SupportedNameSpace", class:0x2, length:0x90, resultlength:0x10, handle:0x418
, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Name
Space_Catalog5\Catalog_Entries\000000000005"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na

me:"Enabled", class:0x2, length:0x90, resultlength:0x10, handle:0x418, path:"\RE


GISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_Catal
og5\Catalog_Entries\000000000005"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Version", class:0x2, length:0x90, resultlength:0x10, handle:0x418, path:"\RE
GISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_Catal
og5\Catalog_Entries\000000000005"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001_Classes\WOW6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9
D}\TreatAs"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"StoresServiceClassInfo", class:0x2, length:0x90, resultlength:0x10, handle:0
x418, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\
NameSpace_Catalog5\Catalog_Entries\000000000005"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ProviderInfo", class:0x2, length:0x90, resultlength:0xC, handle:0x418, path:
"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_C
atalog5\Catalog_Entries\000000000005"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432No
de\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\TreatAs"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ProviderInfo", class:0x2, length:0x90, resultlength:0xC, handle:0x418, path:
"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_C
atalog5\Catalog_Entries\000000000005"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x3
FA
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
18
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"C:\WINDOWS\system32\propsys.dll", handle:0x717E0000
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x717E0000, name:"DllGetClassObject", ordinal:0x0, address:
0x7182EEC0, image:0x0, caller:0x74E6C7CB
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x418, access:0x20019, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Wi
nSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:LdrGetProcedureAddressForCalle
r, status:0xC0000139, module:0x717E0000, name:"DllGetActivationFactory", ordinal
:0x0, image:0x0, caller:0x74E6C7DD
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"LibraryPath", class:0x2, length:0x90, resultlength:0x4E, handle:0x418, path:
"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_C
atalog5\Catalog_Entries\000000000006"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x717E0000, name:"DllCanUnloadNow", ordinal:0x0, address:0x
718330E0, image:0x0, caller:0x74E6C841
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"LibraryPath", class:0x2, length:0x90, resultlength:0x4E, handle:0x418, path:
"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_C
atalog5\Catalog_Entries\000000000006"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"DisplayString", class:0x2, length:0x90, resultlength:0x5C, handle:0x418, pat
h:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace
_Catalog5\Catalog_Entries\000000000006"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:CoCreateInstance, hr:0x0, clsid
:1F486A52-3CB1-48FD-8F50-B8DC300D9F9D, context:0x1, riid:ECF31D61-E474-453C-BEE7
-DE68E441C6D0
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na

me:"DisplayString", class:0x2, length:0x90, resultlength:0x5C, handle:0x418, pat


h:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace
_Catalog5\Catalog_Entries\000000000006"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x717E0000
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"DisplayString", class:0x2, length:0x90, resultlength:0x5C, handle:0x418, pat
h:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace
_Catalog5\Catalog_Entries\000000000006"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"DisplayString", class:0x2, length:0x90, resultlength:0x5C, handle:0x418, pat
h:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace
_Catalog5\Catalog_Entries\000000000006"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ProviderId", class:0x2, length:0x90, resultlength:0x1C, handle:0x418, path:"
\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_Ca
talog5\Catalog_Entries\000000000006"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"AddressFamily", class:0x2, length:0x90, resultlength:0x201CC, handle
:0x418, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameter
s\NameSpace_Catalog5\Catalog_Entries\000000000006"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"SupportedNameSpace", class:0x2, length:0x90, resultlength:0x10, handle:0x418
, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Name
Space_Catalog5\Catalog_Entries\000000000006"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Enabled", class:0x2, length:0x90, resultlength:0x10, handle:0x418, path:"\RE
GISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_Catal
og5\Catalog_Entries\000000000006"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Version", class:0x2, length:0x90, resultlength:0x10, handle:0x418, path:"\RE
GISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_Catal
og5\Catalog_Entries\000000000006"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtOpenSection, status:0xC00000
34, handle:0x0, access:0x4, path:"\Sessions\1\BaseNamedObjects\Global\C:*Program
Data*Microsoft*Windows*Caches*cversions.2"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"StoresServiceClassInfo", class:0x2, length:0x90, resultlength:0x10, handle:0
x418, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\
NameSpace_Catalog5\Catalog_Entries\000000000006"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ProviderInfo", class:0x2, length:0x90, resultlength:0xC, handle:0x418, path:
"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_C
atalog5\Catalog_Entries\000000000006"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ProviderInfo", class:0x2, length:0x90, resultlength:0xC, handle:0x418, path:
"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_C
atalog5\Catalog_Entries\000000000006"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
18
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtOpenSection, status:0xC00000
34, handle:0x0, access:0x4, path:"\Sessions\1\BaseNamedObjects\Local\C:*ProgramD
ata*Microsoft*Windows*Caches*cversions.2"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
14
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x3
8C
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x38C, access:0x1, path:"\REGISTRY\MACHINE\System\CurrentControlSet\Services\Wi
nsock2\Parameters"

pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtOpenSection, status:0xC00000


22, handle:0x0, access:0x4, path:"\Sessions\1\BaseNamedObjects\Global\C:*Program
Data*Microsoft*Windows*Caches*cversions.2.ro"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Ws2_32NumHandleBuckets", class:0x2, length:0x90, resultlength:0x20,
handle:0x38C, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Par
ameters"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Ws2_32SpinCount", class:0x2, length:0x90, resultlength:0x12, handle:
0x38C, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters
"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x3
8C
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtOpenSection, status:0x0, hand
le:0x3F8, access:0x4, path:"\Sessions\1\BaseNamedObjects\Local\C:*ProgramData*Mi
crosoft*Windows*Caches*cversions.2.ro"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtDuplicateObject, status:0x0,
targethandle:0x38C, access:0x0, inherit:0x0, options:0x2, handle:0xFFFFFFFE
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:WSAStartup, ret:0x0, gle:0x0, V
ersionRequested:0x202, Version:0x202, Description:"WinSock 2.0", SystemStatus:"R
unning", MaxSockets:0x0, MaxUdpDg:0x0
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x710000, zerobits:0x0, commitsize:0x0, offset:0x0, viewsize:0x4000, di
sposition:0x1, type:0x0, protect:0x2, handle:0x3F8, path:"\Sessions\1\BaseNamedO
bjects\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:LOG, func:NtOpenSection, status:0xC00000
34, handle:0x0, access:0xF, path:"\KnownDlls32\ondemandconnroutehelper.dll"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtOpenSection, status:0xC00000
22, handle:0x0, access:0x4, path:"\Sessions\1\BaseNamedObjects\Global\C:*Program
Data*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000
000000000078.db"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtOpenSection, status:0x0, hand
le:0x428, access:0x4, path:"\Sessions\1\BaseNamedObjects\Local\C:*ProgramData*Mi
crosoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x00000000000
00078.db"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x20, path:"C:\WINDOWS\SYSTEM32\ondemandconnroutehelper.dll"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0xEA0000, zerobits:0x0, commitsize:0x0, offset:0x0, viewsize:0x45000, d
isposition:0x1, type:0x0, protect:0x2, handle:0x428, path:"\Sessions\1\BaseNamed
Objects\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689
AF493}.2.ver0x0000000000000078.db"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtSetInformationProcess, status
:0x0, class:0xC, length:0x4
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x20, path:"C:\WINDOWS\SysWOW64\propsys.dll"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtSetInformationProcess, status
:0x0, class:0xC, length:0x4
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtOpenFile, status:0x0, handle:
0x414, access:0x100021, iostatus:0x0, information:0x1, share:0x5, options:0x60,
path:"C:\WINDOWS\SYSTEM32\ondemandconnroutehelper.dll"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtCreateSection, status:0x0, ha
ndle:0x418, access:0xF, pageattribs:0x10, sectionattribs:0x1000000, file:0x414
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryFullAttributesFile, stat
us:0x0, allocsize:0x14B000, size:0x14AE48, attribs:0x20, path:"C:\WINDOWS\SysWOW
64\propsys.dll"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x72360000, zerobits:0x0, commitsize:0x0, viewsize:0x12000, disposition
:0x1, type:0x800000, protect:0x4, handle:0x418, path:"C:\WINDOWS\SYSTEM32\ondema
ndconnroutehelper.dll"

pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryFullAttributesFile, stat


us:0x0, allocsize:0x188000, size:0x187698, attribs:0x20, path:"C:\WINDOWS\system
32\propsys.dll"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
18
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
14
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtOpenSection, status:0xC00000
34, handle:0x0, access:0x4, path:"\Sessions\1\BaseNamedObjects\Global\C:*Program
Data*Microsoft*Windows*Caches*cversions.2"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"ondemandconnroutehelper.dll", handle:0x72360000
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x72360000, name:"OnDemandRegisterNotification", ordinal:0x
0, address:0x72362B40, image:0x0, caller:0x702FAF19
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x72360000, name:"OnDemandUnRegisterNotification", ordinal:
0x0, address:0x72367530, image:0x0, caller:0x702FAF2C
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtOpenSection, status:0xC00000
34, handle:0x0, access:0x4, path:"\Sessions\1\BaseNamedObjects\Local\C:*ProgramD
ata*Microsoft*Windows*Caches*cversions.2"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x42C, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\
CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"ProxySettingsPerUser", class:0x2, length:0x90, resultlength:0x29CFC5
0, handle:0x42C, path:"\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\Cur
rentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
2C
pid:4092, tid:4644, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"EnableLegacyAutoProxyFeatures", class:0x2, length:0x90, resultlength
:0x77C8ED50, handle:0x3E4, path:"\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\W
indows\CurrentVersion\Internet Settings"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtOpenSection, status:0xC00000
22, handle:0x0, access:0x4, path:"\Sessions\1\BaseNamedObjects\Global\C:*Program
Data*Microsoft*Windows*Caches*cversions.2.ro"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"BadProxyExpiresTime", class:0x2, length:0x90, resultlength:0x77C8ED5
0, handle:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24639908871001\Software\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x430, iocompletion:0x38, handle:0x42C
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtOpenSection, status:0x0, hand
le:0x438, access:0x4, path:"\Sessions\1\BaseNamedObjects\Local\C:*ProgramData*Mi
crosoft*Windows*Caches*cversions.2.ro"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x730000, zerobits:0x0, commitsize:0x0, offset:0x0, viewsize:0x4000, di
sposition:0x1, type:0x0, protect:0x2, handle:0x438, path:"\Sessions\1\BaseNamedO
bjects\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:LOG, func:NtOpenSection, status:0xC00000
34, handle:0x0, access:0xF, path:"\KnownDlls32\winhttp.dll"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtOpenSection, status:0xC00000
22, handle:0x0, access:0x4, path:"\Sessions\1\BaseNamedObjects\Global\C:*Program
Data*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000
000000000003.db"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x20, path:"C:\WINDOWS\SYSTEM32\winhttp.dll"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtOpenSection, status:0x0, hand
le:0x43C, access:0x4, path:"\Sessions\1\BaseNamedObjects\Local\C:*ProgramData*Mi

crosoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x00000000000
00003.db"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtOpenFile, status:0x0, handle:
0x434, access:0x100021, iostatus:0x0, information:0x1, share:0x5, options:0x60,
path:"C:\WINDOWS\SYSTEM32\winhttp.dll"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x2AD0000, zerobits:0x0, commitsize:0x0, offset:0x0, viewsize:0x8E000,
disposition:0x1, type:0x0, protect:0x2, handle:0x43C, path:"\Sessions\1\BaseName
dObjects\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39
C3FDA2}.2.ver0x0000000000000003.db"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtCreateSection, status:0x0, ha
ndle:0x440, access:0xF, pageattribs:0x10, sectionattribs:0x1000000, file:0x434
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtSetInformationProcess, status
:0x0, class:0xC, length:0x4
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x74760000, zerobits:0x0, commitsize:0x0, viewsize:0x9B000, disposition
:0x1, type:0x800000, protect:0x4, handle:0x440, path:"C:\WINDOWS\SYSTEM32\winhtt
p.dll"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x20, path:"C:\WINDOWS\SysWOW64\propsys.dll"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtSetInformationProcess, status
:0x0, class:0xC, length:0x4
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
40
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
34
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryFullAttributesFile, stat
us:0x0, allocsize:0x14B000, size:0x14AE48, attribs:0x20, path:"C:\WINDOWS\SysWOW
64\propsys.dll"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"winhttp.dll", handle:0x74760000
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74760000, name:"WinHttpCreateProxyResolver", ordinal:0x0,
address:0x7478EE00, image:0x0, caller:0x70307CF5
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74760000, name:"WinHttpGetProxyForUrlEx", ordinal:0x0, ad
dress:0x7478EC70, image:0x0, caller:0x70307D0B
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74760000, name:"WinHttpGetProxyResult", ordinal:0x0, addr
ess:0x747C0C00, image:0x0, caller:0x70307D22
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74760000, name:"WinHttpFreeProxyResult", ordinal:0x0, add
ress:0x74791F10, image:0x0, caller:0x70307D39
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74760000, name:"WinHttpCloseHandle", ordinal:0x0, address
:0x7477B3F0, image:0x0, caller:0x70307D50
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74760000, name:"WinHttpOpen", ordinal:0x0, address:0x7479
3AA0, image:0x0, caller:0x70307D67
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74760000, name:"WinHttpSetStatusCallback", ordinal:0x0, a
ddress:0x74777180, image:0x0, caller:0x70307D7E
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74760000, name:"WinHttpResetAutoProxy", ordinal:0x0, addr
ess:0x74799E70, image:0x0, caller:0x70307D95
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryFullAttributesFile, stat
us:0x0, allocsize:0x188000, size:0x187698, attribs:0x20, path:"C:\WINDOWS\system
32\propsys.dll"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74760000, name:"WinHttpSetOption", ordinal:0x0, address:0

x74778010, image:0x0, caller:0x70307DAC


pid:4092, tid:4644, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"AutoProxyDetectType", class:0x2, length:0x90, resultlength:0x0, hand
le:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\So
ftware\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2E1D0F0, class:0x3, length:0x14
pid:4092, tid:4644, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DisableBranchCache", class:0x2, length:0x90, resultlength:0x34, hand
le:0x3F4, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Current
Version\Internet Settings"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x444, access:0x1, path:"\Registry\Machine\Software\Microsoft\Windows\Windows Err
or Reporting\WMR"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"user32.dll", handle:0x75050000
pid:4092, tid:8800, tick:0x33D6FFF, lvl:LOG, func:BaseThreadInitThunk, log:"New
thread started (via BaseThreadInitThunk) at address: 0x77C3C6D0, parameter: 0x76
52D8"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x75050000, name:"IsImmersiveProcess", ordinal:0x0, address
:0x7506FEA0, image:0x0, caller:0x7030B393
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Disable", class:0x2, length:0x13, resultlength:0x10, handle:0x444, path:"\RE
GISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Windows Error Reporting\WM
R"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:LdrUnloadDll, status:0x0, handl
e:0x75050000
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:New_NtQueryInformationToken::<
lambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0xC0000023, token:
0x448, class:0x1, length:0x0, returnlength:0x24
pid:4092, tid:4644, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"UseFirstAvailable", class:0x2, length:0x90, resultlength:0x34, handl
e:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\Sof
tware\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x448, c
lass:0x1, length:0x24, returnlength:0x24, sid:"S-1-5-21-2360094602-2602383397-24
63990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
48
pid:4092, tid:4644, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"CombineFalseStartData", class:0x2, length:0x90, resultlength:0x34, h
andle:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001
\Software\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DisableFalseStartBlocklist", class:0x2, length:0x90, resultlength:0x
34, handle:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887
-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"EnableHttp2Upgrade", class:0x2, length:0x90, resultlength:0x34, hand
le:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\So
ftware\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtOpenKey, status:0xC0000034,
handle:0x0, access:0x1, path:"\Registry\User\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\Windows Error Reporting\WMR"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
44
pid:4092, tid:4644, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DuoProtocols", class:0x2, length:0x90, resultlength:0x29CF4AC, handl

e:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\Sof
tware\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2E1D0F0, class:0x3, length:0x14
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2E1D0F0, class:0x3, length:0x14
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2E1D0F0, class:0x3, length:0x14
pid:4092, tid:4644, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"EnableSpdyDebugAsserts", class:0x2, length:0x90, resultlength:0x34,
handle:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-100
1\Software\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2E1D0F0, class:0x3, length:0x14
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2E1D0F0, class:0x3, length:0x14
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2E1D0F0, class:0x3, length:0x14
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2E1D0F0, class:0x3, length:0x14
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2E1D0F0, class:0x3, length:0x14
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2E1D0F0, class:0x3, length:0x14
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2E1D0F0, class:0x3, length:0x14
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2E1D0F0, class:0x3, length:0x14
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2E1D0F0, class:0x3, length:0x14
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2E1D0F0, class:0x3, length:0x14
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2E1D0F0, class:0x3, length:0x14
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2E1D0F0, class:0x3, length:0x14
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x404, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24639908
87-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2E1D0F0, class:0x3, length:0x14
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2E1D0F0, class:0x3, length:0x14
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2E1D0F0, class:0x3, length:0x14
pid:4092, tid:4644, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"EnableNpn", class:0x2, length:0x90, resultlength:0x29CFC50, handle:0
x404, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWA
RE\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2E1D0F0, class:0x3, length:0x14
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2E1D0F0, class:0x3, length:0x14
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
04
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2E1D0F0, class:0x3, length:0x14
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"ondemandconnroutehelper.dll", handle:0x72360000
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryVirtualMemory, status:0x

0, address:0x2E1D0F0, class:0x3, length:0x14


pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x72360000, name:"GetInterfaceContextTableForHostName", ord
inal:0x0, address:0x72363490, image:0x0, caller:0x702FADF3
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x72360000, name:"FreeInterfaceContextTable", ordinal:0x0,
address:0x72363D40, image:0x0, caller:0x702FAE09
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:WSAStartup, ret:0x0, gle:0x0, V
ersionRequested:0x202, Version:0x202, Description:"WinSock 2.0", SystemStatus:"R
unning", MaxSockets:0x0, MaxUdpDg:0x0
pid:4092, tid:4644, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20119, path:"\REGISTRY\MACHINE\Software\Policies\Microsof
t\PeerDist\Service"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x444, access:0x1, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVe
rsion\Policies\Explorer"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtDuplicateObject, status:0x0,
targethandle:0x41C, access:0x0, inherit:0x0, options:0x2, handle:0xFFFFFFFE
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DontShowSuperHidden", class:0x2, length:0x90, resultlength:0x19DA14,
handle:0x444, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Windows\CurrentVersion
\Policies\Explorer"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20119, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows
NT\CurrentVersion\PeerDist\Service"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"C:\WINDOWS\system32\mswsock.dll", handle:0x73700000
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
44
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x73700000, name:"WSPStartup", ordinal:0x0, address:0x7370D
350, image:0x0, caller:0x775F7454
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"
pid:4092, tid:9004, tick:0x33D6FFF, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0xEF0000, zerobits:0x0, commitsize:0x0, offset:0x220000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x404, access:0x20019, path:"\REGISTRY\MACHINE\SYSTEM\CurrentControlSet\Service
s\Winsock\Parameters"
pid:4092, tid:9004, tick:0x33D6FFF, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5A0000
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Transports", class:0x2, length:0x90, resultlength:0x42, handle:0x404, path:"
\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Winsock\Parameters"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x444, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24639908
87-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\"
pid:4092, tid:9004, tick:0x33D6FFF, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5A0000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Transports", class:0x2, length:0x90, resultlength:0x42, handle:0x404, path:"
\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Winsock\Parameters"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ShellState", class:0x2, length:0x90, resultlength:0x30, handle:0x444, path:"
\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\Software\Microsoft
\Windows\CurrentVersion\Explorer"
pid:4092, tid:9004, tick:0x33D6FFF, lvl:OK, func:NtUnmapViewOfSection, status:0x

0, address:0xEF0000
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
04
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ShellState", class:0x2, length:0x90, resultlength:0x30, handle:0x444, path:"
\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\Software\Microsoft
\Windows\CurrentVersion\Explorer"
pid:4092, tid:9004, tick:0x33D6FFF, lvl:LOG, func:RecurseRegistryConfig, log:"Du
plicate regkey Connections will not be added as it is at lower layer."
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
44
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x404, access:0x20019, path:"\REGISTRY\MACHINE\System\CurrentControlSet\Service
s\Psched\Parameters\Winsock"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0x8000
0005, name:"Mapping", class:0x2, length:0x90, resultlength:0xA4, handle:0x404, p
ath:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Psched\Parameters\Winsock"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x444, access:0x1, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVe
rsion\Policies\Explorer"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0x8000
0005, name:"Mapping", class:0x2, length:0x90, resultlength:0xA4, handle:0x404, p
ath:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Psched\Parameters\Winsock"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"NoWebView", class:0x2, length:0x90, resultlength:0x19D9A8, handle:0x
444, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Windows\CurrentVersion\Policies\
Explorer"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Mapping", class:0x2, length:0xA4, resultlength:0xA4, handle:0x404, path:"\RE
GISTRY\MACHINE\SYSTEM\ControlSet001\Services\Psched\Parameters\Winsock"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
44
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
04
pid:4092, tid:9004, tick:0x33D6FFF, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0xEF0000, zerobits:0x0, commitsize:0x0, offset:0x220000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:9004, tick:0x33D6FFF, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5A0000
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x404, access:0x20019, path:"\REGISTRY\MACHINE\SYSTEM\CurrentControlSet\Service
s\Winsock\Setup Migration\Providers"
pid:4092, tid:9004, tick:0x33D6FFF, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5A0000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:9004, tick:0x33D6FFF, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0xEF0000
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x440, access:0x20019, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Wi
nsock\Setup Migration\Providers\Psched"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x44C, access:0x1, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVe
rsion\Policies\Explorer"
pid:4092, tid:9004, tick:0x33D6FFF, lvl:LOG, func:_FaultInValuesIf, log:"Duplica
te reg value SavedLegacySettings will not be added as it is at lower layer. type
: 0x1"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na

me:"WinSock 2.0 Provider ID", class:0x2, length:0x90, resultlength:0x1C, handle:


0x440, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Winsock\Setup Migra
tion\Providers\Psched"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
40
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"ClassicShell", class:0x2, length:0x90, resultlength:0x19D9A8, handle
:0x44C, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Windows\CurrentVersion\Polici
es\Explorer"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
04
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
4C
pid:4092, tid:9004, tick:0x33D6FFF, lvl:OK, func:NtCreateKey, status:0x0, handle
:0x450, access:0x1, title:0x0, class:"", options:0x0, disposition:0x2, path:"\RE
GISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\Software\Microsoft\Wi
ndows\CurrentVersion\Internet Settings\Connections"
pid:4092, tid:9004, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"DefaultConnectionSettings", class:0x2, length:0x90, resultlength:0x44, handl
e:0x450, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\Sof
tware\Microsoft\Windows\CurrentVersion\Internet Settings\Connections"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x404, access:0x20019, path:"\REGISTRY\MACHINE\System\CurrentControlSet\Service
s\Tcpip\Parameters\Winsock"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"
pid:4092, tid:9004, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"DefaultConnectionSettings", class:0x2, length:0x90, resultlength:0x44, handl
e:0x450, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\Sof
tware\Microsoft\Windows\CurrentVersion\Internet Settings\Connections"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Mapping", class:0x2, length:0x90, resultlength:0x74, handle:0x404, path:"\RE
GISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Winsock"
pid:4092, tid:9004, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
50
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Mapping", class:0x2, length:0x90, resultlength:0x74, handle:0x404, path:"\RE
GISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Winsock"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x44C, access:0x1, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVe
rsion\Policies\Explorer"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
04
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"SeparateProcess", class:0x2, length:0x90, resultlength:0x19D9A8, han
dle:0x44C, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Windows\CurrentVersion\Pol
icies\Explorer"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
4C
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x404, access:0x20019, path:"\REGISTRY\MACHINE\System\CurrentControlSet\Service
s\Tcpip6\Parameters\Winsock"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtCreateKey, status:0x0, handle
:0x440, access:0x1, title:0x0, class:"", options:0x0, disposition:0x2, path:"\RE
GISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\Software\Microsoft\Wi
ndows\CurrentVersion\Internet Settings\Connections"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Mapping", class:0x2, length:0x90, resultlength:0x74, handle:0x404, path:"\RE
GISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip6\Parameters\Winsock"

pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034


, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"DefaultConnectionSettings", class:0x2, length:0x90, resultlength:0x44, handl
e:0x440, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\Sof
tware\Microsoft\Windows\CurrentVersion\Internet Settings\Connections"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Mapping", class:0x2, length:0x90, resultlength:0x74, handle:0x404, path:"\RE
GISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip6\Parameters\Winsock"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
04
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"DefaultConnectionSettings", class:0x2, length:0x90, resultlength:0x44, handl
e:0x440, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\Sof
tware\Microsoft\Windows\CurrentVersion\Internet Settings\Connections"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x44C, access:0x1, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVe
rsion\Policies\Explorer"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
40
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"NoNetCrawling", class:0x2, length:0x90, resultlength:0x19D9A8, handl
e:0x44C, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Windows\CurrentVersion\Polic
ies\Explorer"
pid:4092, tid:11200, tick:0x33D6FFF, lvl:LOG, func:BaseThreadInitThunk, log:"New
thread started (via BaseThreadInitThunk) at address: 0x77C3C6D0, parameter: 0x7
652D8"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x404, access:0x20019, path:"\REGISTRY\MACHINE\SYSTEM\CurrentControlSet\Service
s\Winsock\Setup Migration\Providers"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
4C
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x444, access:0x20019, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Wi
nsock\Setup Migration\Providers\Tcpip6"
pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:LdrResolveDelayLoadedAPI, stat
us:0x0, module:0x701C0000
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"WinSock 2.0 Provider ID", class:0x2, length:0x90, resultlength:0x1C, handle:
0x444, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Winsock\Setup Migra
tion\Providers\Tcpip6"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
44
pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:NtDeviceIoControlFile, status:
0x0, event:0x45C, iostatus:0x0, information:0x50, code:0x120007, inlen:0x30, out
len:0x4, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
04
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x460, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24639908
87-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced"
pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x
45C
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Hidden", class:0x2, length:0x90, resultlength:0x10, handle:0x460, path:"\REG
ISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Win

dows\CurrentVersion\Explorer\Advanced"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:LOG, func:BaseThreadInitThunk, log:"New
thread started (via BaseThreadInitThunk) at address: 0x77C3C6D0, parameter: 0x76
52D8"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x404, access:0x20019, path:"\REGISTRY\MACHINE\System\CurrentControlSet\Service
s\Tcpip6\Parameters\Winsock"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ShowCompColor", class:0x2, length:0x90, resultlength:0x10, handle:0x460, pat
h:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Micros
oft\Windows\CurrentVersion\Explorer\Advanced"
pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:NtDeviceIoControlFile, status:
0x0, event:0x45C, iostatus:0x0, information:0x50, code:0x120007, inlen:0x30, out
len:0x8, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"HideFileExt", class:0x2, length:0x90, resultlength:0x10, handle:0x460, path:
"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsof
t\Windows\CurrentVersion\Explorer\Advanced"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"MinSockaddrLength", class:0x2, length:0x90, resultlength:0x10, handle:0x404,
path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip6\Parameters\Winsock
"
pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x
45C
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"DontPrettyPath", class:0x2, length:0x90, resultlength:0x10, handle:0x460, pa
th:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Micro
soft\Windows\CurrentVersion\Explorer\Advanced"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"MaxSockaddrLength", class:0x2, length:0x90, resultlength:0x10, handle:0x404,
path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip6\Parameters\Winsock
"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ShowInfoTip", class:0x2, length:0x90, resultlength:0x10, handle:0x460, path:
"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsof
t\Windows\CurrentVersion\Explorer\Advanced"
pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:NtDeviceIoControlFile, status:
0x0, event:0x45C, iostatus:0x0, information:0x50, code:0x120007, inlen:0x30, out
len:0x4, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"HideIcons", class:0x2, length:0x90, resultlength:0x10, handle:0x460, path:"\
REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\
Windows\CurrentVersion\Explorer\Advanced"
pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x
45C
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"UseDelayedAcceptance", class:0x2, length:0x90, resultlength:0x10, handle:0x4
04, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip6\Parameters\Wins
ock"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"MapNetDrvBtn", class:0x2, length:0x90, resultlength:0x10, handle:0x460, path
:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microso
ft\Windows\CurrentVersion\Explorer\Advanced"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
04
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"WebView", class:0x2, length:0x90, resultlength:0x10, handle:0x460, path:"\RE
GISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Wi
ndows\CurrentVersion\Explorer\Advanced"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:New_NtQueryInformationToken::<l

ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x404, c


lass:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:NtDeviceIoControlFile, status:
0x0, event:0x45C, iostatus:0x0, information:0x68, code:0x12000F, inlen:0x38, out
len:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Filter", class:0x2, length:0x90, resultlength:0x10, handle:0x460, path:"\REG
ISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Win
dows\CurrentVersion\Explorer\Advanced"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
04
pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x
45C
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ShowSuperHidden", class:0x2, length:0x90, resultlength:0x10, handle:0x460, p
ath:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Micr
osoft\Windows\CurrentVersion\Explorer\Advanced"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"SeparateProcess", class:0x2, length:0x90, resultlength:0x10, handle:0x460, p
ath:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Micr
osoft\Windows\CurrentVersion\Explorer\Advanced"
pid:4092, tid:11200, tick:0x33D6FFF, lvl:LOG, func:NtDeviceIoControlFile, status
:0xC0000225, event:0x45C, iostatus:0x31DF0BC, information:0x20, code:0x12000F, i
nlen:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"NoNetCrawling", class:0x2, length:0x90, resultlength:0x10, handle:0x
460, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWAR
E\Microsoft\Windows\CurrentVersion\Explorer\Advanced"
pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x
45C
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"AutoCheckSelect", class:0x2, length:0x90, resultlength:0x10, handle:0x460, p
ath:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Micr
osoft\Windows\CurrentVersion\Explorer\Advanced"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtCreateFile, status:0x0, handl
e:0x404, access:0xC0140000, iostatus:0x0, information:0x0, attribs:0x0, share:0x
3, disposition:0x3, options:0x0, path:"\Device\Afd\Endpoint"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"IconsOnly", class:0x2, length:0x90, resultlength:0x10, handle:0x460, path:"\
REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\
Windows\CurrentVersion\Explorer\Advanced"
pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:NtDeviceIoControlFile, status:
0x0, event:0x45C, iostatus:0x0, information:0x68, code:0x12000F, inlen:0x38, out
len:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ShowTypeOverlay", class:0x2, length:0x90, resultlength:0x10, handle:0x460, p
ath:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Micr
osoft\Windows\CurrentVersion\Explorer\Advanced"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x408, iostatus:0x0, information:0x10, code:0x1207B, inlen:0x10, outle
n:0x10, handle:0x404, path:"\Device\Afd\Endpoint"
pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x
45C
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ShowStatusBar", class:0x2, length:0x90, resultlength:0x10, handle:0x460, pat
h:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Micros
oft\Windows\CurrentVersion\Explorer\Advanced"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x408, iostatus:0x0, information:0x10, code:0x1207B, inlen:0x10, outle
n:0x10, handle:0x404, path:"\Device\Afd\Endpoint"

pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4


60
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x408, iostatus:0x0, information:0x0, code:0x12047, inlen:0xC4, outlen
:0x1C, handle:0x404, path:"\Device\Afd\Endpoint"
pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:NtDeviceIoControlFile, status:
0x0, event:0x45C, iostatus:0x0, information:0x50, code:0x120007, inlen:0x30, out
len:0x4, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x92, handle:0x386, path:"\REGISTRY\USER\S-1-5-21
-2360094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x386, path:"\REGISTRY\USER\S-1-5-21-23
60094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x
45C
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x408, iostatus:0x0, information:0x0, code:0x120BF, inlen:0x18, outlen
:0x0, handle:0x404, path:"\Device\Afd\Endpoint"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x408, iostatus:0x0, information:0x0, code:0x12047, inlen:0xC4, outlen
:0x1C, handle:0x404, path:"\Device\Afd\Endpoint"
pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:NtDeviceIoControlFile, status:
0x0, event:0x460, iostatus:0x0, information:0x50, code:0x120007, inlen:0x30, out
len:0x8, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001_Classes\.exe"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x408, iostatus:0x0, information:0xB8, code:0x120B3, inlen:0x2, outlen
:0x200, handle:0x404, path:"\Device\Afd\Endpoint"
pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x
460
pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:NtDeviceIoControlFile, status:
0x0, event:0x460, iostatus:0x0, information:0x50, code:0x120007, inlen:0x30, out
len:0x4, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x464, access:0x20019, path:"\Registry\Machine\Software\Classes\.exe"
pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x
460
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtDeviceIoControlFile, status:0
x103, event:0x408, iostatus:0x0, information:0x34, code:0x120BF, inlen:0x18, out
len:0xDC, handle:0x404, path:"\Device\Afd\Endpoint"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0x52, handle:0x466, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\.exe"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
04
pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:NtDeviceIoControlFile, status:
0x0, event:0x460, iostatus:0x0, information:0x68, code:0x12000F, inlen:0x38, out
len:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x466, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\.exe"
pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x
460
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0

pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handl


e:0x460, access:0x20019, path:"\REGISTRY\MACHINE\System\Setup"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\.exe"
pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, n
ame:"SystemSetupInProgress", class:0x2, length:0x90, resultlength:0x10, handle:0
x460, path:"\REGISTRY\MACHINE\SYSTEM\Setup"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"", class:0x2, length:0x90, resultlength:0x1C, handle:0x466, path:"\REGISTRY\
MACHINE\SOFTWARE\Classes\.exe"
pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x
460
pid:4092, tid:8800, tick:0x33D6FFF, lvl:LOG, func:NtOpenSection, status:0xC00000
34, handle:0x0, access:0xF, path:"\KnownDlls32\WINNSI.DLL"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x92, handle:0x386, path:"\REGISTRY\USER\S-1-5-21
-2360094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x386, path:"\REGISTRY\USER\S-1-5-21-23
60094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001_Classes\exefile"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x46C, access:0x20019, path:"\Registry\Machine\Software\Classes\exefile"
pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handl
e:0x468, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990
887-1001\Software\Microsoft\windows\CurrentVersion\Internet Settings"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x58, handle:0x46E, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\exefile"
pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, n
ame:"MigrateProxy", class:0x2, length:0x90, resultlength:0x10, handle:0x468, pat
h:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\Software\Micros
oft\windows\CurrentVersion\Internet Settings"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:LOG, func:NtQueryAttributesFile, status:
0xC0000034, path:"C:\Users\i92segoa\Desktop\Firefox SEO\WINNSI.DLL"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x46E, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\exefile"
pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x
468
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_Classes\exefile\CurVer"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\exefile\CurVe
r"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x58, handle:0x46E, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\exefile"
pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handl
e:0x468, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246
3990887-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtQueryAttributesFile, status:0

x0, attribs:0x20, path:"C:\WINDOWS\SYSTEM32\WINNSI.DLL"


pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x46E, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\exefile"
pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, n
ame:"ProxyEnable", class:0x2, length:0x90, resultlength:0x10, handle:0x468, path
:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\Software\Microso
ft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:11200, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC00
00034, name:"ProxyServer", class:0x2, length:0x90, resultlength:0x10, handle:0x4
68, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\Software
\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:11200, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC00
00034, name:"ProxyOverride", class:0x2, length:0x90, resultlength:0x10, handle:0
x468, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\Softwa
re\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001_Classes\exefile"
pid:4092, tid:11200, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC00
00034, name:"AutoConfigURL", class:0x2, length:0x90, resultlength:0x10, handle:0
x468, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\Softwa
re\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x470, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\exefile\"
pid:4092, tid:11200, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC00
00034, name:"AutoDetect", class:0x2, length:0x90, resultlength:0x10, handle:0x46
8, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\Software\
Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
6E
pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x
468
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x58, handle:0x472, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\exefile"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x472, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\exefile"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtOpenFile, status:0x0, handle:
0x45C, access:0x100021, iostatus:0x0, information:0x1, share:0x5, options:0x60,
path:"C:\WINDOWS\SYSTEM32\WINNSI.DLL"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_Classes\exefile\ShellEx\IconHandler"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtCreateSection, status:0x0, ha
ndle:0x468, access:0xF, pageattribs:0x10, sectionattribs:0x1000000, file:0x45C
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\exefile\Shell
Ex\IconHandler"
pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:NtCreateKey, status:0x0, handl
e:0x46C, access:0x1, title:0x0, class:"", options:0x0, disposition:0x2, path:"\R

EGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\Software\Microsoft\W
indows\CurrentVersion\Internet Settings\Connections"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x92, handle:0x386, path:"\REGISTRY\USER\S-1-5-21
-2360094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, n
ame:"SavedLegacySettings", class:0x2, length:0x90, resultlength:0x44, handle:0x4
6C, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\Software
\Microsoft\Windows\CurrentVersion\Internet Settings\Connections"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x72470000, zerobits:0x0, commitsize:0x0, viewsize:0x8000, disposition:
0x1, type:0x800000, protect:0x4, handle:0x468, path:"C:\WINDOWS\SYSTEM32\WINNSI.
DLL"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x386, path:"\REGISTRY\USER\S-1-5-21-23
60094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, n
ame:"SavedLegacySettings", class:0x2, length:0x90, resultlength:0x44, handle:0x4
6C, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\Software
\Microsoft\Windows\CurrentVersion\Internet Settings\Connections"
pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x
46C
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001_Classes\SystemFileAssociations\.exe"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
68
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x474, access:0x20019, path:"\Registry\Machine\Software\Classes\SystemFileAssoc
iations\.exe"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
5C
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x80, handle:0x476, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\SystemFileAssociations\.exe"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x476, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\SystemFileAssociations\.exe"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x736A0000
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_Classes\SystemFileAssociations\.exe\ShellEx\IconHandler"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtDuplicateObject, status:0x0,
targethandle:0x468, access:0x0, inherit:0x0, options:0x2, handle:0xFFFFFFFE
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\SystemFileAss
ociations\.exe\ShellEx\IconHandler"
pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:NtCreateKey, status:0x0, handl
e:0x404, access:0x1, title:0x0, class:"", options:0x0, disposition:0x2, path:"\R
EGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\Software\Microsoft\W
indows\CurrentVersion\Internet Settings\Connections"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0x58, handle:0x472, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\exefile"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtDeviceIoControlFile, status:0

x0, event:0x46C, iostatus:0x0, information:0x68, code:0x12000F, inlen:0x38, outl


en:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x472, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\exefile"
pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, n
ame:"DefaultConnectionSettings", class:0x2, length:0x90, resultlength:0x44, hand
le:0x404, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\So
ftware\Microsoft\Windows\CurrentVersion\Internet Settings\Connections"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
6C
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, n
ame:"DefaultConnectionSettings", class:0x2, length:0x90, resultlength:0x44, hand
le:0x404, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\So
ftware\Microsoft\Windows\CurrentVersion\Internet Settings\Connections"
pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x
404
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\exefile"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DocObject", class:0x2, length:0x90, resultlength:0x0, handle:0x472,
path:"\REGISTRY\MACHINE\SOFTWARE\Classes\exefile"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x58, handle:0x472, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\exefile"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x472, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\exefile"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_Classes\exefile\DocObject"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\exefile\DocOb
ject"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0x80, handle:0x476, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\SystemFileAssociations\.exe"
pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:NtCreateKey, status:0x0, handl
e:0x404, access:0x20006, title:0x0, class:"", options:0x0, disposition:0x2, path
:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\Software\Microso
ft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x476, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\SystemFileAssociations\.exe"
pid:4092, tid:8264, tick:0x33D6FFF, lvl:LOG, func:BaseThreadInitThunk, log:"New
thread started (via BaseThreadInitThunk) at address: 0x77C3C6D0, parameter: 0x76
52D8"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:New_NtQueryInformationToken::<l

ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF


FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:8264, tick:0x33D6FFF, lvl:OK, func:NtDuplicateObject, status:0x0,
targethandle:0x480, access:0x0, inherit:0x0, options:0x2, handle:0xFFFFFFFE
pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:NtSetValueKey, status:0x0, nam
e:"ProxyEnable", index:0x0, type:0x4, size:0x4, handle:0x404, path:"\REGISTRY\US
ER\S-1-5-21-2360094602-2602383397-2463990887-1001\Software\Microsoft\Windows\Cur
rentVersion\Internet Settings"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\SystemFileAssociations\.exe"
pid:4092, tid:11200, tick:0x33D6FFF, lvl:LOG, func:NtDeleteValueKey, status:0xC0
000034, name:"ProxyServer", handle:0x404, path:"\REGISTRY\USER\S-1-5-21-23600946
02-2602383397-2463990887-1001\Software\Microsoft\Windows\CurrentVersion\Internet
Settings"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DocObject", class:0x2, length:0x90, resultlength:0x0, handle:0x476,
path:"\REGISTRY\MACHINE\SOFTWARE\Classes\SystemFileAssociations\.exe"
pid:4092, tid:11200, tick:0x33D6FFF, lvl:LOG, func:NtDeleteValueKey, status:0xC0
000034, name:"ProxyOverride", handle:0x404, path:"\REGISTRY\USER\S-1-5-21-236009
4602-2602383397-2463990887-1001\Software\Microsoft\Windows\CurrentVersion\Intern
et Settings"
pid:4092, tid:556, tick:0x33D6FFF, lvl:LOG, func:BaseThreadInitThunk, log:"New t
hread started (via BaseThreadInitThunk) at address: 0x77C3C6D0, parameter: 0x765
2D8"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x80, handle:0x476, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\SystemFileAssociations\.exe"
pid:4092, tid:11200, tick:0x33D6FFF, lvl:LOG, func:NtDeleteValueKey, status:0xC0
000034, name:"AutoConfigURL", handle:0x404, path:"\REGISTRY\USER\S-1-5-21-236009
4602-2602383397-2463990887-1001\Software\Microsoft\Windows\CurrentVersion\Intern
et Settings"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x476, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\SystemFileAssociations\.exe"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:11200, tick:0x33D6FFF, lvl:LOG, func:NtDeleteValueKey, status:0xC0
000034, name:"AutoDetect", handle:0x404, path:"\REGISTRY\USER\S-1-5-21-236009460
2-2602383397-2463990887-1001\Software\Microsoft\Windows\CurrentVersion\Internet
Settings"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_Classes\SystemFileAssociations\.exe\DocObject"
pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x
404
pid:4092, tid:556, tick:0x33D6FFF, lvl:OK, func:NtDuplicateObject, status:0x0, t
argethandle:0x488, access:0x0, inherit:0x0, options:0x2, handle:0xFFFFFFFE
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\SystemFileAss
ociations\.exe\DocObject"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0x58, handle:0x472, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\exefile"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x472, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\exefile"

pid:4092, tid:556, tick:0x33D6FFF, lvl:OK, func:New_NtQueryInformationToken::<la


mbda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFFF
A, class:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\exefile"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"BrowseInPlace", class:0x2, length:0x90, resultlength:0x0, handle:0x4
72, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\exefile"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x58, handle:0x472, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\exefile"
pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:NtCreateKey, status:0x0, handl
e:0x404, access:0x1, title:0x0, class:"", options:0x0, disposition:0x2, path:"\R
EGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\Software\Microsoft\W
indows\CurrentVersion\Internet Settings\Connections"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x472, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\exefile"
pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, n
ame:"SavedLegacySettings", class:0x2, length:0x90, resultlength:0x44, handle:0x4
04, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\Software
\Microsoft\Windows\CurrentVersion\Internet Settings\Connections"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, n
ame:"SavedLegacySettings", class:0x2, length:0x90, resultlength:0x44, handle:0x4
04, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\Software
\Microsoft\Windows\CurrentVersion\Internet Settings\Connections"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_Classes\exefile\BrowseInPlace"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\exefile\Brows
eInPlace"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x458, iocompletion:0x38, handle:0x410
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0x80, handle:0x476, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\SystemFileAssociations\.exe"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
6C
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x476, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\SystemFileAssociations\.exe"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x46C, iostatus:0x0, information:0x68, code:0x12000F, inlen:0x38, outl
en:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:NtCreateKey, status:0x0, handl
e:0x498, access:0x2, title:0x0, class:"", options:0x0, disposition:0x2, path:"\R

EGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\Software\Microsoft\W
indows\CurrentVersion\Internet Settings\Connections"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
6C
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\SystemFileAssociations\.exe"
pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:NtSetValueKey, status:0x0, nam
e:"SavedLegacySettings", index:0x0, type:0x3, size:0x38, handle:0x498, path:"\RE
GISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\Software\Microsoft\Wi
ndows\CurrentVersion\Internet Settings\Connections"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"BrowseInPlace", class:0x2, length:0x90, resultlength:0x0, handle:0x4
76, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\SystemFileAssociations\.exe"
pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x
498
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x80, handle:0x476, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\SystemFileAssociations\.exe"
pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x
404
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x476, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\SystemFileAssociations\.exe"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x498, iocompletion:0x38, handle:0x460
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x701C0000
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
6C
pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:LdrResolveDelayLoadedAPI, stat
us:0x0, module:0x701C0000
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_Classes\SystemFileAssociations\.exe\BrowseInPlace"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x46C, iostatus:0x0, information:0x68, code:0x12000F, inlen:0x38, outl
en:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x72170000
pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:LdrResolveDelayLoadedAPI, stat
us:0x0, module:0x72170000
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
6C
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\SystemFileAss
ociations\.exe\BrowseInPlace"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:NtDuplicateObject, status:0x0,
targethandle:0x46C, access:0x0, inherit:0x0, options:0x2, handle:0xFFFFFFFE
pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:NtDuplicateObject, status:0x0,
targethandle:0x4A4, access:0x0, inherit:0x0, options:0x2, handle:0xFFFFFFFE
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0x52, handle:0x466, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\.exe"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF

FA, class:0x1D, length:0x4, returnlength:0x4


pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x466, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\.exe"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\.exe"
pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x
4AC
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4B8, iocompletion:0x38, handle:0x4AC
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Content Type", class:0x2, length:0x90, resultlength:0x3E, handle:0x466, path
:"\REGISTRY\MACHINE\SOFTWARE\Classes\.exe"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
9C
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x58, handle:0x472, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\exefile"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x49C, iostatus:0x0, information:0x68, code:0x12000F, inlen:0x38, outl
en:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x472, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\exefile"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
9C
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:NtCreateKey, status:0x0, handle
:0x4BC, access:0xF003F, title:0x0, class:"", options:0x1, disposition:0x2, path:
"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsof
t\Windows\CurrentVersion\OnDemandInterfaceCache"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_Classes\exefile\Clsid"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x72360000
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\exefile\Clsid
"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:LOG, func:New_NtQueryInformationToken::<
lambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0xC0000023, token:
0xFFFFFFFC, class:0x27, length:0x0, returnlength:0x68
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x80, handle:0x476, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\SystemFileAssociations\.exe"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FC, class:0x27, length:0x68, returnlength:0x68
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x476, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\SystemFileAssociations\.exe"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:New_NtQueryInformationToken::<l

ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF


FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4CC, iocompletion:0x38, handle:0x4C0
pid:4092, tid:1488, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"ForceAppTestMode", class:0x2, length:0x90, resultlength:0x25B, handl
e:0x4BC, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOF
TWARE\Microsoft\Windows\CurrentVersion\OnDemandInterfaceCache"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_Classes\SystemFileAssociations\.exe\Clsid"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
BC
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
9C
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\SystemFileAss
ociations\.exe\Clsid"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x49C, iostatus:0x0, information:0x50, code:0x120007, inlen:0x30, outl
en:0x4, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0x58, handle:0x472, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\exefile"
pid:4092, tid:11200, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC000003
4, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\Microsoft\WCMSvc
\Selection"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
9C
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x472, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\exefile"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x49C, iostatus:0x0, information:0x50, code:0x120007, inlen:0x30, outl
en:0x8, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
9C
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\exefile"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x49C, iostatus:0x0, information:0x50, code:0x120007, inlen:0x30, outl
en:0x4, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"IsShortcut", class:0x2, length:0x90, resultlength:0x0, handle:0x472,
path:"\REGISTRY\MACHINE\SOFTWARE\Classes\exefile"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x4D4, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVe
rsion\Internet Settings"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
9C
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0x80, handle:0x476, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\SystemFileAssociations\.exe"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryKey, status:0x0, class:0

x7, length:0x4, resultlength:0x4, handle:0x476, path:"\REGISTRY\MACHINE\SOFTWARE


\Classes\SystemFileAssociations\.exe"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"ShareCredsWithWinHttp", class:0x2, length:0x90, resultlength:0x1D4,
handle:0x4D4, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Cur
rentVersion\Internet Settings"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x49C, iostatus:0x0, information:0x68, code:0x12000F, inlen:0x38, outl
en:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
D4
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
9C
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\SystemFileAssociations\.exe"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
D4
pid:4092, tid:8800, tick:0x33D6FFF, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x49C, iostatus:0x2C9F23C, information:0x20, code:0x12000F, in
len:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"IsShortcut", class:0x2, length:0x90, resultlength:0x0, handle:0x476,
path:"\REGISTRY\MACHINE\SOFTWARE\Classes\SystemFileAssociations\.exe"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
D8
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
9C
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:New_CheckTokenMembership::<lamb
da_02604bca4152832ac92161eb66d89101>::operator (), ret:0x1, gle:0x0, SidToCheck:
"S-1-5-18", IsMember:0x0
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0x58, handle:0x472, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\exefile"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x49C, iostatus:0x0, information:0x68, code:0x12000F, inlen:0x38, outl
en:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
D8
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x472, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\exefile"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
9C
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
D4
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:New_CheckTokenMembership::<lamb
da_02604bca4152832ac92161eb66d89101>::operator (), ret:0x1, gle:0x0, SidToCheck:
"S-1-5-19", IsMember:0x0
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x49C, iostatus:0x0, information:0x50, code:0x120007, inlen:0x30, outl
en:0x4, handle:0x2F4, path:"\??\Nsi"

pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4


D4
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\exefile"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
9C
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
D8
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:New_CheckTokenMembership::<lamb
da_02604bca4152832ac92161eb66d89101>::operator (), ret:0x1, gle:0x0, SidToCheck:
"S-1-5-20", IsMember:0x0
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"AlwaysShowExt", class:0x2, length:0x90, resultlength:0x0, handle:0x4
72, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\exefile"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x4DC, iostatus:0x0, information:0x50, code:0x120007, inlen:0x30, outl
en:0x8, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
DC
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0x80, handle:0x476, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\SystemFileAssociations\.exe"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x4DC, iostatus:0x0, information:0x50, code:0x120007, inlen:0x30, outl
en:0x4, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x476, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\SystemFileAssociations\.exe"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x4D8, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVe
rsion\Internet Settings\WinHttp"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
DC
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:1488, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DisableBranchCache", class:0x2, length:0x90, resultlength:0x1D4, han
dle:0x4D8, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Curren
tVersion\Internet Settings\WinHttp"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
D8
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x4DC, iostatus:0x0, information:0x68, code:0x12000F, inlen:0x38, outl
en:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\SystemFileAssociations\.exe"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
DC
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"AlwaysShowExt", class:0x2, length:0x90, resultlength:0x0, handle:0x4
76, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\SystemFileAssociations\.exe"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x4D8, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVe
rsion\Internet Settings\WinHttp"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0x58, handle:0x472, path:"\REGISTRY\MACHINE\SOFTW

ARE\Classes\exefile"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x472, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\exefile"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DisableAutoProxyAuth", class:0x2, length:0x90, resultlength:0x1D4, h
andle:0x4D8, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Curr
entVersion\Internet Settings\WinHttp"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
D8
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\exefile"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"NeverShowExt", class:0x2, length:0x90, resultlength:0x0, handle:0x47
2, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\exefile"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x74760000
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0x80, handle:0x476, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\SystemFileAssociations\.exe"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"winhttp.dll", handle:0x74760000
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x476, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\SystemFileAssociations\.exe"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x74760000
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:WSAStartup, ret:0x0, gle:0x0, V
ersionRequested:0x101, Version:0x102, Description:"WinSock 2.0", SystemStatus:"R
unning", MaxSockets:0x7FFF, MaxUdpDg:0xFFBB
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"ondemandconnroutehelper.dll", handle:0x72360000
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\SystemFileAssociations\.exe"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x72360000, name:"GetInterfaceContextTableForHostName", ord
inal:0x0, address:0x72363490, image:0x0, caller:0x747925AB
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x72360000, name:"FreeInterfaceContextTable", ordinal:0x0,
address:0x72363D40, image:0x0, caller:0x747925C1
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"NeverShowExt", class:0x2, length:0x90, resultlength:0x0, handle:0x47
6, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\SystemFileAssociations\.exe"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x4DC, c
lass:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
66
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
DC

pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4


72
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
76
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x74760000
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x474, iocompletion:0x38, handle:0x4DC
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"winhttp.dll", handle:0x74760000
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74760000, name:"WinHttpCreateProxyResolver", ordinal:0x0,
address:0x7478EE00, image:0x0, caller:0x7478C5F1
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x464, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\Curre
ntVersion\Explorer\FolderDescriptions"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74760000, name:"WinHttpGetProxyForUrlEx", ordinal:0x0, ad
dress:0x7478EC70, image:0x0, caller:0x7478C607
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74760000, name:"WinHttpGetProxyResult", ordinal:0x0, addr
ess:0x747C0C00, image:0x0, caller:0x7478C61E
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x4E0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\W
indows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99
A87C641}"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74760000, name:"WinHttpFreeProxyResult", ordinal:0x0, add
ress:0x74791F10, image:0x0, caller:0x7478C635
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
64
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74760000, name:"WinHttpCloseHandle", ordinal:0x0, address
:0x7477B3F0, image:0x0, caller:0x7478C64C
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74760000, name:"WinHttpOpen", ordinal:0x0, address:0x7479
3AA0, image:0x0, caller:0x7478C663
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Category", class:0x2, length:0x90, resultlength:0x10, handle:0x4E0, path:"\R
EGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\F
olderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74760000, name:"WinHttpSetStatusCallback", ordinal:0x0, a
ddress:0x74777180, image:0x0, caller:0x7478C67A
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74760000, name:"WinHttpResetAutoProxy", ordinal:0x0, addr
ess:0x74799E70, image:0x0, caller:0x7478C691
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Name", class:0x2, length:0x90, resultlength:0x1C, handle:0x4E0, path:"\REGIS
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Folde
rDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74760000, name:"WinHttpSetOption", ordinal:0x0, address:0
x74778010, image:0x0, caller:0x7478C6A8
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"ParentFolder", class:0x2, length:0x90, resultlength:0x10, handle:0x4
E0, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersio
n\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Description", class:0x2, length:0x90, resultlength:0x10, handle:0x4E

0, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion
\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"RelativePath", class:0x2, length:0x90, resultlength:0x1C, handle:0x4E0, path
:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explor
er\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x4E4, access:0x2000000, path:"\REGISTRY\MACHINE\SYSTEM\CurrentControlSet\Servi
ces\WinHttpAutoProxySvc\Parameters"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"ParsingName", class:0x2, length:0x90, resultlength:0x1C, handle:0x4E
0, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion
\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ProxyDllFile", class:0x2, length:0x90, resultlength:0x50, handle:0x4E4, path
:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinHttpAutoProxySvc\Parameters
"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"InfoTip", class:0x2, length:0x90, resultlength:0x1C, handle:0x4E0, p
ath:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Exp
lorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
E4
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"LocalizedName", class:0x2, length:0x90, resultlength:0x60, handle:0x4E0, pat
h:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explo
rer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Icon", class:0x2, length:0x90, resultlength:0x5C, handle:0x4E0, path:"\REGIS
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Folde
rDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x4E4, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\Curre
ntVersion\Internet Settings\WinHttp"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Security", class:0x2, length:0x90, resultlength:0x5C, handle:0x4E0,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Ex
plorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"AutoProxyAutoLogonIfChallenged", class:0x2, length:0x90, resultlengt
h:0x0, handle:0x4E4, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Wind
ows\CurrentVersion\Internet Settings\WinHttp"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
E4
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"StreamResource", class:0x2, length:0x90, resultlength:0x5C, handle:0
x4E0, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVers
ion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"StreamResourceType", class:0x2, length:0x90, resultlength:0x5C, hand
le:0x4E0, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Current
Version\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x4E4, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\windows\Curre
ntVersion\Internet Settings"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"LocalRedirectOnly", class:0x2, length:0x90, resultlength:0x5C, handl
e:0x4E0, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentV
ersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000

0034, name:"WinHttpLowerCaseHost", class:0x2, length:0x90, resultlength:0x20, ha


ndle:0x4E4, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Curre
ntVersion\Internet Settings"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Roamable", class:0x2, length:0x90, resultlength:0x10, handle:0x4E0, path:"\R
EGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\F
olderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
E4
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"PreCreate", class:0x2, length:0x90, resultlength:0x10, handle:0x4E0, path:"\
REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\
FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Stream", class:0x2, length:0x90, resultlength:0x10, handle:0x4E0, pa
th:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Expl
orer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"PublishExpandedPath", class:0x2, length:0x90, resultlength:0x10, handle:0x4E
0, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion
\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x74760000
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DefinitionFlags", class:0x2, length:0x90, resultlength:0x10, handle:
0x4E0, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVer
sion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Attributes", class:0x2, length:0x90, resultlength:0x10, handle:0x4E0, path:"
\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer
\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:NtOpenEvent, status:0x0, handle
:0x4EC, access:0x100000, path:"\Sessions\1\BaseNamedObjects\Global\SvcctrlStartE
vent_A3752DX"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtOpenEvent, status:0x0, handle
:0x4E8, access:0x100000, path:"\Sessions\1\BaseNamedObjects\Global\SvcctrlStartE
vent_A3752DX"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
EC
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"FolderTypeID", class:0x2, length:0x90, resultlength:0x10, handle:0x4
E0, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersio
n\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
E8
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"InitFolderHandler", class:0x2, length:0x90, resultlength:0x10, handl
e:0x4E0, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentV
ersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x4F8, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\W
indows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99
A87C641}\PropertyBag"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
E0
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
E8

pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:New_NtQueryInformationToken::<l


ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x4E0, c
lass:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:OpenSCManagerW, ret:0x7E4BA8, g
le:0x0, desiredAccess:0x1
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:OpenSCManagerW, ret:0x7E4E00, g
le:0x0, desiredAccess:0x1
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x4FC, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24639908
87-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\K
nownFolders"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
FC
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x500, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246399
0887-1001"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x4E8, access:0x1, path:"\REGISTRY\MACHINE\System\CurrentControlSet\Control\SQM
ServiceList"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"SQMServiceList", class:0x2, length:0x90, resultlength:0x42, handle:0x4E8, pa
th:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\SQMServiceList"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x504, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folder
s"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
E8
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x5
00
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:OpenServiceW, ret:0x7E49C8, gle
:0x0, SCManager:0x7E4BA8, serviceName:"WinHttpAutoProxySvc", desiredAccess:0x94
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:OpenServiceW, ret:0x7E4A68, gle
:0x0, SCManager:0x7E4E00, serviceName:"WinHttpAutoProxySvc", desiredAccess:0x94
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Desktop", class:0x2, length:0x90, resultlength:0x38, handle:0x504, path:"\RE
GISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Wi
ndows\CurrentVersion\Explorer\User Shell Folders"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
E0
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:CloseServiceHandle, ret:0x1, gl
e:0x0, SCObject:0x7E4BA8
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x5
04
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:CloseServiceHandle, ret:0x1, gl
e:0x0, SCObject:0x7E4E00
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x74760000
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x776F0000
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x500, iocompletion:0x38, handle:0x4FC
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:CoCreateInstance, hr:0x0, clsid

:1F486A52-3CB1-48FD-8F50-B8DC300D9F9D, context:0x1, riid:ECF31D61-E474-453C-BEE7


-DE68E441C6D0
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:LdrUnloadDll, status:0x0, handl
e:0x74760000
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0xF
FFFFFFC
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x74760000
pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x500, iocompletion:0x38, handle:0x4FC
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:LdrUnloadDll, status:0x0, handl
e:0x74760000
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0xF
FFFFFFC
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:QueryServiceStatus, ret:0x1, gl
e:0x0, service:0x7E4A68, serviceType:0x20, currentState:0x4, controlsAccepted:0x
41, win32ExitCode:0x0, serviceSpecificExitCode:0x0, checkPoint:0x0, waitHint:0x0
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:QueryServiceStatus, ret:0x1, gl
e:0x0, service:0x7E49C8, serviceType:0x20, currentState:0x4, controlsAccepted:0x
41, win32ExitCode:0x0, serviceSpecificExitCode:0x0, checkPoint:0x0, waitHint:0x0
pid:4092, tid:11200, tick:0x33D6FFF, lvl:LOG, func:QueryServiceStatusEx, log:"Ca
ll to New_QueryServiceStatusEx made: Ret: 0x1."
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
F4
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
E0
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:CloseServiceHandle, ret:0x1, gl
e:0x0, SCObject:0x7E49C8
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
E8
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:CloseServiceHandle, ret:0x1, gl
e:0x0, SCObject:0x7E4A68
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtOpenSection, status:0xC00000
34, handle:0x0, access:0x4, path:"\Sessions\1\BaseNamedObjects\Local\C:*Users*i9
2segoa*AppData*Local*Microsoft*Windows*Caches*cversions.1"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x5
04
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4E0, iocompletion:0x38, handle:0x4E4
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4F4, iocompletion:0x38, handle:0x464
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x508, iocompletion:0x38, handle:0x49C
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x50C, iocompletion:0x38, handle:0x470
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x510, iocompletion:0x38, handle:0x4D8
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x514, iocompletion:0x38, handle:0x4D8
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtOpenSection, status:0x0, hand
le:0x520, access:0x4, path:"\Sessions\1\BaseNamedObjects\Local\C:*Users*i92segoa
*AppData*Local*Microsoft*Windows*Caches*cversions.1.ro"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0xEF0000, zerobits:0x0, commitsize:0x0, offset:0x0, viewsize:0x4000, di
sposition:0x1, type:0x0, protect:0x2, handle:0x520, path:"\Sessions\1\BaseNamedO
bjects\C:*Users*i92segoa*AppData*Local*Microsoft*Windows*Caches*cversions.1.ro"
pid:4092, tid:556, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x50
8
pid:4092, tid:556, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x51
0

pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x


50C
pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x
514
pid:4092, tid:556, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4E
4
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:LdrUnloadDll, status:0x0, handl
e:0x701C0000
pid:4092, tid:556, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x49
C
pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x
464
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:LdrUnloadDll, status:0x0, handl
e:0x701C0000
pid:4092, tid:556, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x50
4
pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x
470
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtOpenSection, status:0xC00000
34, handle:0x0, access:0x4, path:"\Sessions\1\BaseNamedObjects\Local\C:*Users*i9
2segoa*AppData*Local*Microsoft*Windows*Caches*{AFBF9F1A-8EE8-4C77-AF34-C647E37CA
0D9}.1.ver0x0000000000000012.db"
pid:4092, tid:556, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4E
0
pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x
4E8
pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x
4F4
pid:4092, tid:1488, tick:0x33D6FFF, lvl:LOG, func:NtOpenSection, status:0xC00000
34, handle:0x0, access:0xF, path:"\KnownDlls32\urlmon.dll"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:LOG, func:NtQueryAttributesFile, status:
0xC0000034, path:"C:\Users\i92segoa\Desktop\Firefox SEO\urlmon.dll"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtCreateFile, status:0x0, handl
e:0x524, access:0x80100080, iostatus:0x0, information:0x1, attribs:0x0, share:0x
1, disposition:0x1, options:0x60, path:"C:\Users\i92segoa\AppData\Local\Microsof
t\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000012.
db"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryInformationFile, status:
0x0, iostatus:0x0, information:0x18, length:0x18, class:0x5, handle:0x524, path:
"C:\Users\i92segoa\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF
34-C647E37CA0D9}.1.ver0x0000000000000012.db"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:New_NtQueryInformationToken::<
lambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0xC0000023, token:
0x528, class:0x1, length:0x0, returnlength:0x24
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x20, path:"C:\WINDOWS\SYSTEM32\urlmon.dll"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x528, c
lass:0x1, length:0x24, returnlength:0x24, sid:"S-1-5-21-2360094602-2602383397-24
63990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x5
28
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtCreateSection, status:0x0, ha
ndle:0x528, access:0xF0005, pageattribs:0x2, sectionattribs:0x8000000, file:0x52
4, path:"\Sessions\1\BaseNamedObjects\Local\C:*Users*i92segoa*AppData*Local*Micr
osoft*Windows*Caches*{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000
012.db"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x5
24, path:"C:\Users\i92segoa\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE
8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000012.db"

pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:NtOpenFile, status:0x0, handle:


0x4F4, access:0x100021, iostatus:0x0, information:0x1, share:0x5, options:0x60,
path:"C:\WINDOWS\SYSTEM32\urlmon.dll"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x35A0000, zerobits:0x0, commitsize:0x0, offset:0x0, viewsize:0x1A9000,
disposition:0x1, type:0x0, protect:0x2, handle:0x528, path:"C:\Users\i92segoa\A
ppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.v
er0x0000000000000012.db"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:NtCreateSection, status:0x0, ha
ndle:0x4E8, access:0xF, pageattribs:0x10, sectionattribs:0x1000000, file:0x4F4
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x73500000, zerobits:0x0, commitsize:0x0, viewsize:0x17D000, dispositio
n:0x1, type:0x800000, protect:0x4, handle:0x4E8, path:"C:\WINDOWS\SYSTEM32\urlmo
n.dll"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x5
28
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0xF
FFFFFFC
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x5
20
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtUnmapViewOfSectionEx, status:
0x0, address:0xEF0000
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
E8
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
F4
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0xEF0000, zerobits:0x0, commitsize:0x0, offset:0x1E0000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5A0000
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5A0000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0xEF0000
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtCreateFile, status:0x0, handl
e:0x518, access:0x80100080, iostatus:0x0, information:0x1, attribs:0x0, share:0x
7, disposition:0x1, options:0x64, path:"C:\Users\i92segoa\Desktop\desktop.ini"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:NtSetInformationProcess, status
:0x0, class:0x23, length:0x70
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryInformationFile, status:
0x0, iostatus:0x0, information:0x18, length:0x18, class:0x5, handle:0x518, path:
"C:\Users\i92segoa\Desktop\desktop.ini"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtReadFile, status:0x0, iostatu
s:0x0, information:0x11A, length:0x11C, handle:0x518, path:"C:\Users\i92segoa\De
sktop\desktop.ini"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryInformationFile, status:
0x0, iostatus:0x0, information:0x28, length:0x28, class:0x4, handle:0x518, path:
"C:\Users\i92segoa\Desktop\desktop.ini"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x5
18
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x701C0000
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtOpenSection, status:0x0, hand
le:0x518, access:0x6, path:"\Sessions\1\BaseNamedObjects\Global\windows_shell_gl
obal_counters"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0xEF0000, zerobits:0x0, commitsize:0x0, offset:0x0, viewsize:0x1000, di
sposition:0x1, type:0x0, protect:0x4, handle:0x518, path:"\BaseNamedObjects\wind

ows_shell_global_counters"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x464, access:0x1, path:"\REGISTRY\MACHINE\Software\Policies\Microsoft\Windows\
CurrentVersion\Internet Settings\"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Security_HKLM_only", class:0x2, length:0x90, resultlength:0x1D4, han
dle:0x464, path:"\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVe
rsion\Internet Settings"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
64
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x4E0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\Curre
ntVersion\Explorer\FolderDescriptions"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_I
GNORE_POLICIES_ZONEMAP_IF_ESC_ENABLED_KB918915"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x504, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\W
indows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC
332AEAE}"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
E0
pid:4092, tid:1488, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft
\Internet Explorer\Main\FeatureControl\FEATURE_IGNORE_POLICIES_ZONEMAP_IF_ESC_EN
ABLED_KB918915"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Category", class:0x2, length:0x90, resultlength:0x10, handle:0x504, path:"\R
EGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\F
olderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Name", class:0x2, length:0x90, resultlength:0x20, handle:0x504, path:"\REGIS
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Folde
rDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ParentFolder", class:0x2, length:0x90, resultlength:0x5A, handle:0x504, path
:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explor
er\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies\Microsof
t\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Description", class:0x2, length:0x90, resultlength:0x5A, handle:0x50
4, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion
\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"RelativePath", class:0x2, length:0x90, resultlength:0x44, handle:0x504, path
:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explor
er\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"ParsingName", class:0x2, length:0x90, resultlength:0x44, handle:0x50
4, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion
\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"InfoTip", class:0x2, length:0x90, resultlength:0x44, handle:0x504, p
ath:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Exp
lorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339

7-2463990887-1001\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Se
ttings\ZoneMap\Domains\"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"LocalizedName", class:0x2, length:0x90, resultlength:0x44, handle:0x
504, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersi
on\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Icon", class:0x2, length:0x90, resultlength:0x44, handle:0x504, path
:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explor
er\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Security", class:0x2, length:0x90, resultlength:0x44, handle:0x504,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Ex
plorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies\Microsof
t\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"StreamResource", class:0x2, length:0x90, resultlength:0x44, handle:0
x504, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVers
ion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"StreamResourceType", class:0x2, length:0x90, resultlength:0x44, hand
le:0x504, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Current
Version\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\ZoneMap\Ranges\"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"LocalRedirectOnly", class:0x2, length:0x90, resultlength:0x44, handl
e:0x504, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentV
ersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Roamable", class:0x2, length:0x90, resultlength:0x44, handle:0x504,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Ex
plorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"PreCreate", class:0x2, length:0x90, resultlength:0x10, handle:0x504, path:"\
REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\
FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001\ZoneMap\Ranges\"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Stream", class:0x2, length:0x90, resultlength:0x10, handle:0x504, pa
th:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Expl
orer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"PublishExpandedPath", class:0x2, length:0x90, resultlength:0x10, handle:0x50
4, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion
\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\ZoneMap\Ranges\"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DefinitionFlags", class:0x2, length:0x90, resultlength:0x10, handle:
0x504, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVer
sion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"ntdll.dll", module:0x77C10000
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Attributes", class:0x2, length:0x90, resultlength:0x10, handle:0x504

, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\
Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77C10000, name:"RtlGetDeviceFamilyInfoEnum", ordinal:0x0,
address:0x77C7B110, image:0x0, caller:0x72A1504F
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"FolderTypeID", class:0x2, length:0x90, resultlength:0x10, handle:0x5
04, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersio
n\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"InitFolderHandler", class:0x2, length:0x90, resultlength:0x10, handl
e:0x504, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentV
ersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Micro
soft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF
-BD1DC332AEAE}\PropertyBag"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_Z
ONES_CHECK_ZONEMAP_POLICY_KB941001"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x5
04
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x504, c
lass:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:1488, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft
\Internet Explorer\Main\FeatureControl\FEATURE_ZONES_CHECK_ZONEMAP_POLICY_KB9410
01"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x4E0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24639908
87-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\K
nownFolders"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
E0
pid:4092, tid:1488, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\Software\Policies\Microsoft\Wi
ndows\CurrentVersion\Internet Settings\ZoneMap"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:1488, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settin
gs\ZoneMap"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x49C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246399
0887-1001"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x4E4, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folder
s"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:NtCreateKey, status:0x0, handle
:0x520, access:0x2001F, title:0x0, class:"", options:0x0, disposition:0x2, path:
"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\Software\Microsof

t\Windows\CurrentVersion\Internet Settings\ZoneMap\"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
9C
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}", class:0x2, length:0x90, res
ultlength:0x0, handle:0x4E4, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397
-2463990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell F
olders"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x528, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\Curre
ntVersion\Internet Settings\ZoneMap\"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x4E0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\Curre
ntVersion\Explorer\FolderDescriptions"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Se
ttings\ZoneMap\"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x49C, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\W
indows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF6
5729F3D}"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
E0
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Category", class:0x2, length:0x90, resultlength:0x10, handle:0x49C, path:"\R
EGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\F
olderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies\Microsof
t\Windows\CurrentVersion\Internet Settings\ZoneMap\"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Name", class:0x2, length:0x90, resultlength:0x1C, handle:0x49C, path:"\REGIS
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Folde
rDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"ParentFolder", class:0x2, length:0x90, resultlength:0x10, handle:0x4
9C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersio
n\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Description", class:0x2, length:0x90, resultlength:0x10, handle:0x49
C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion
\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies\Microsof
t\Windows\CurrentVersion\Internet Settings\ZoneMap\"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"RelativePath", class:0x2, length:0x90, resultlength:0x2C, handle:0x49C, path
:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explor
er\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"ParsingName", class:0x2, length:0x90, resultlength:0x2C, handle:0x49
C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion
\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"InfoTip", class:0x2, length:0x90, resultlength:0x2C, handle:0x49C, p
ath:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Exp
lorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24

63990887-1001\Software\Policies\Microsoft\Internet Explorer"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"LocalizedName", class:0x2, length:0x90, resultlength:0x2C, handle:0x
49C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersi
on\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Icon", class:0x2, length:0x90, resultlength:0x2C, handle:0x49C, path
:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explor
er\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Security", class:0x2, length:0x90, resultlength:0x2C, handle:0x49C,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Ex
plorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x524, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Internet Explorer\Security"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"StreamResource", class:0x2, length:0x90, resultlength:0x2C, handle:0
x49C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVers
ion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"StreamResourceType", class:0x2, length:0x90, resultlength:0x2C, hand
le:0x49C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Current
Version\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DisableSecuritySettingsCheck", class:0x2, length:0x90, resultlength:
0x0, handle:0x524, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246399088
7-1001\SOFTWARE\Microsoft\Internet Explorer\Security"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"LocalRedirectOnly", class:0x2, length:0x90, resultlength:0x2C, handl
e:0x49C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentV
ersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x5
24
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Roamable", class:0x2, length:0x90, resultlength:0x2C, handle:0x49C,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Ex
plorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"PreCreate", class:0x2, length:0x90, resultlength:0x2C, handle:0x49C,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\E
xplorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Stream", class:0x2, length:0x90, resultlength:0x2C, handle:0x49C, pa
th:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Expl
orer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x524, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Internet Expl
orer\Security"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"PublishExpandedPath", class:0x2, length:0x90, resultlength:0x2C, han
dle:0x49C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Curren
tVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DisableSecuritySettingsCheck", class:0x2, length:0x90, resultlength:
0x0, handle:0x524, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Intern
et Explorer\Security"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DefinitionFlags", class:0x2, length:0x90, resultlength:0x2C, handle:
0x49C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVer

sion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
24
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Attributes", class:0x2, length:0x90, resultlength:0x2C, handle:0x49C
, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\
Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x7361B000, class:0x0, length:0x1C, resultlength:0x1C
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"FolderTypeID", class:0x2, length:0x90, resultlength:0x2C, handle:0x4
9C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersio
n\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"SspiCli.dll", handle:0x74940000
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74940000, name:"GetUserNameExW", ordinal:0x0, address:0x7
494C5F0, image:0x0, caller:0x735747A8
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"InitFolderHandler", class:0x2, length:0x90, resultlength:0x2C, handl
e:0x49C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentV
ersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Micro
soft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A
-E3EF65729F3D}\PropertyBag"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x4
9C
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x49C, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24639908
87-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtCreateSection, status:0x40000
000, handle:0x524, access:0xF0007, size:0x1C, pageattribs:0x4, sectionattribs:0x
8000000, path:"\Sessions\1\BaseNamedObjects\Local\UrlZonesSM_i92segoa"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\K
nownFolders"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x3750000, zerobits:0x0, commitsize:0x0, offset:0x0, viewsize:0x1000, d
isposition:0x1, type:0x0, protect:0x4, handle:0x524, path:"\Sessions\1\BaseNamed
Objects\UrlZonesSM_i92segoa"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x4
9C
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x52C, access:0x20019, path:"\REGISTRY\MACHINE\System\Setup"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"AppData", class:0x2, length:0x90, resultlength:0x48, handle:0x4E4, path:"\RE
GISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Wi
ndows\CurrentVersion\Explorer\User Shell Folders"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"SystemSetupInProgress", class:0x2, length:0x90, resultlength:0x10, handle:0x
52C, path:"\REGISTRY\MACHINE\SYSTEM\Setup"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
2C
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x52C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
04

pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x4


E4
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x530, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
30
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x530, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
30
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x530, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x4E4, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\Curre
ntVersion\Explorer\FolderDescriptions"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
30
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x530, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\W
indows\CurrentVersion\Explorer\FolderDescriptions\{F42EE2D3-909F-4907-8871-4C22F
C0BF756}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x534, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x4
E4
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
34
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Category", class:0x2, length:0x90, resultlength:0x10, handle:0x530, path:"\R
EGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\F
olderDescriptions\{F42EE2D3-909F-4907-8871-4C22FC0BF756}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x534, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
34
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Name", class:0x2, length:0x90, resultlength:0x2C, handle:0x530, path:"\REGIS
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Folde
rDescriptions\{F42EE2D3-909F-4907-8871-4C22FC0BF756}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
2C
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"ParentFolder", class:0x2, length:0x90, resultlength:0x10, handle:0x5
30, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersio
n\Explorer\FolderDescriptions\{F42EE2D3-909F-4907-8871-4C22FC0BF756}"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Description", class:0x2, length:0x90, resultlength:0x10, handle:0x53
0, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion
\Explorer\FolderDescriptions\{F42EE2D3-909F-4907-8871-4C22FC0BF756}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies\Microsof
t\Windows\CurrentVersion\Internet Settings\Zones\"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"RelativePath", class:0x2, length:0x90, resultlength:0x20, handle:0x530, path
:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explor

er\FolderDescriptions\{F42EE2D3-909F-4907-8871-4C22FC0BF756}"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0x8000
0005, name:"ParsingName", class:0x2, length:0x90, resultlength:0xBC, handle:0x53
0, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion
\Explorer\FolderDescriptions\{F42EE2D3-909F-4907-8871-4C22FC0BF756}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Se
ttings\Zones\"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ParsingName", class:0x2, length:0xBC, resultlength:0xBC, handle:0x530, path:
"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explore
r\FolderDescriptions\{F42EE2D3-909F-4907-8871-4C22FC0BF756}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies\Microsof
t\Windows\CurrentVersion\Internet Settings\Zones\"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"InfoTip", class:0x2, length:0x90, resultlength:0xBC, handle:0x530, p
ath:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Exp
lorer\FolderDescriptions\{F42EE2D3-909F-4907-8871-4C22FC0BF756}"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"LocalizedName", class:0x2, length:0x90, resultlength:0x60, handle:0x530, pat
h:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explo
rer\FolderDescriptions\{F42EE2D3-909F-4907-8871-4C22FC0BF756}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Se
ttings\Zones\"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Icon", class:0x2, length:0x90, resultlength:0x5C, handle:0x530, path:"\REGIS
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Folde
rDescriptions\{F42EE2D3-909F-4907-8871-4C22FC0BF756}"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Security", class:0x2, length:0x90, resultlength:0x5C, handle:0x530,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Ex
plorer\FolderDescriptions\{F42EE2D3-909F-4907-8871-4C22FC0BF756}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies\Microsof
t\Windows\CurrentVersion\Internet Settings\Zones\"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"StreamResource", class:0x2, length:0x90, resultlength:0x5C, handle:0
x530, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVers
ion\Explorer\FolderDescriptions\{F42EE2D3-909F-4907-8871-4C22FC0BF756}"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"StreamResourceType", class:0x2, length:0x90, resultlength:0x5C, hand
le:0x530, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Current
Version\Explorer\FolderDescriptions\{F42EE2D3-909F-4907-8871-4C22FC0BF756}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x52C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"LocalRedirectOnly", class:0x2, length:0x90, resultlength:0x5C, handl
e:0x530, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentV
ersion\Explorer\FolderDescriptions\{F42EE2D3-909F-4907-8871-4C22FC0BF756}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x0, class:0x0, length:0x120, resultlength:0x12, handle:0x52C, path:"\REGISTR
Y\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Windows
\CurrentVersion\Internet Settings\Zones"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Roamable", class:0x2, length:0x90, resultlength:0x5C, handle:0x530,

path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Ex
plorer\FolderDescriptions\{F42EE2D3-909F-4907-8871-4C22FC0BF756}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtCreateMutant, status:0x400000
00, handle:0x534, access:0x1F0001, owner:0x0, path:"\Sessions\1\BaseNamedObjects
\Local\ZonesCacheCounterMutex"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"PreCreate", class:0x2, length:0x90, resultlength:0x10, handle:0x530, path:"\
REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\
FolderDescriptions\{F42EE2D3-909F-4907-8871-4C22FC0BF756}"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Stream", class:0x2, length:0x90, resultlength:0x10, handle:0x530, pa
th:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Expl
orer\FolderDescriptions\{F42EE2D3-909F-4907-8871-4C22FC0BF756}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x53C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"PublishExpandedPath", class:0x2, length:0x90, resultlength:0x10, han
dle:0x530, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Curren
tVersion\Explorer\FolderDescriptions\{F42EE2D3-909F-4907-8871-4C22FC0BF756}"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DefinitionFlags", class:0x2, length:0x90, resultlength:0x10, handle:
0x530, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVer
sion\Explorer\FolderDescriptions\{F42EE2D3-909F-4907-8871-4C22FC0BF756}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies\Microsof
t\Windows\CurrentVersion\Internet Settings\Zones\0"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Attributes", class:0x2, length:0x90, resultlength:0x10, handle:0x530, path:"
\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer
\FolderDescriptions\{F42EE2D3-909F-4907-8871-4C22FC0BF756}"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"FolderTypeID", class:0x2, length:0x90, resultlength:0x10, handle:0x5
30, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersio
n\Explorer\FolderDescriptions\{F42EE2D3-909F-4907-8871-4C22FC0BF756}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Se
ttings\Zones\0"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"InitFolderHandler", class:0x2, length:0x90, resultlength:0x10, handl
e:0x530, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentV
ersion\Explorer\FolderDescriptions\{F42EE2D3-909F-4907-8871-4C22FC0BF756}"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x4E4, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\W
indows\CurrentVersion\Explorer\FolderDescriptions\{F42EE2D3-909F-4907-8871-4C22F
C0BF756}\PropertyBag"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies\Microsof
t\Windows\CurrentVersion\Internet Settings\Zones\0"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
30
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x530, c
lass:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x540, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Flags", class:0x2, length:0x90, resultlength:0x10, handle:0x540, path:"\REGI

STRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Wind
ows\CurrentVersion\Internet Settings\Zones\0"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x538, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24639908
87-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
40
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
3C
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\K
nownFolders"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
38
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1, class:0x0, length:0x120, resultlength:0x12, handle:0x52C, path:"\REGISTR
Y\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Windows
\CurrentVersion\Internet Settings\Zones"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x540, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies\Microsof
t\Windows\CurrentVersion\Internet Settings\Zones\1"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x53C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246399
0887-1001"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Se
ttings\Zones\1"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x544, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folder
s"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies\Microsof
t\Windows\CurrentVersion\Internet Settings\Zones\1"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
3C
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"{F42EE2D3-909F-4907-8871-4C22FC0BF756}", class:0x2, length:0x90, res
ultlength:0x0, handle:0x544, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397
-2463990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell F
olders"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x548, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x538, c
lass:0x1, length:0x40, returnlength:0x24, sid:"S-1-5-21-2360094602-2602383397-24
63990887-1001", attributes:0x0
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Flags", class:0x2, length:0x90, resultlength:0x10, handle:0x548, path:"\REGI
STRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Wind

ows\CurrentVersion\Internet Settings\Zones\1"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x53C, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows NT\Cu
rrentVersion\ProfileList\S-1-5-21-2360094602-2602383397-2463990887-1001"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x54C, access:0x2001F, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\
"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ProfileImagePath", class:0x2, length:0x90, resultlength:0x30, handle:0x53C,
path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\ProfileList
\S-1-5-21-2360094602-2602383397-2463990887-1001"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtSetValueKey, status:0x0, name
:"ProxyBypass", index:0x0, type:0x4, size:0x4, handle:0x54C, path:"\REGISTRY\USE
R\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Windows\Curr
entVersion\Internet Settings\ZoneMap"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ProfileImagePath", class:0x2, length:0x90, resultlength:0x30, handle:0x53C,
path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\ProfileList
\S-1-5-21-2360094602-2602383397-2463990887-1001"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
3C
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtSetValueKey, status:0x0, name
:"IntranetName", index:0x0, type:0x4, size:0x4, handle:0x54C, path:"\REGISTRY\US
ER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Windows\Cur
rentVersion\Internet Settings\ZoneMap"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
38
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
30
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtSetValueKey, status:0x0, name
:"UNCAsIntranet", index:0x0, type:0x4, size:0x4, handle:0x54C, path:"\REGISTRY\U
SER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Windows\Cu
rrentVersion\Internet Settings\ZoneMap"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
44
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtSetValueKey, status:0x0, name
:"AutoDetect", index:0x0, type:0x4, size:0x4, handle:0x54C, path:"\REGISTRY\USER
\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Windows\Curre
ntVersion\Internet Settings\ZoneMap"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
4C
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
48
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
40
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x2, class:0x0, length:0x120, resultlength:0x12, handle:0x52C, path:"\REGISTR
Y\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Windows
\CurrentVersion\Internet Settings\Zones"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x3760000, zerobits:0x0, commitsize:0x0, offset:0x1E0000, viewsize:0x10
000, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5A0000
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding directory Portalbe firefox with flags: 6."
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x540, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2"

pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034


, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies\Microsof
t\Windows\CurrentVersion\Internet Settings\Zones\2"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
44
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5A0000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Se
ttings\Zones\2"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x3760000
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x3760000, zerobits:0x0, commitsize:0x0, offset:0x1E0000, viewsize:0x10
000, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies\Microsof
t\Windows\CurrentVersion\Internet Settings\Zones\2"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5A0000
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5A0000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x548, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x3760000
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Flags", class:0x2, length:0x90, resultlength:0x10, handle:0x548, path:"\REGI
STRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Wind
ows\CurrentVersion\Internet Settings\Zones\2"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
48
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
40
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x3, class:0x0, length:0x120, resultlength:0x12, handle:0x52C, path:"\REGISTR
Y\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Windows
\CurrentVersion\Internet Settings\Zones"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x540, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtCreateFile, status:0x0, handl
e:0x544, access:0x80100080, iostatus:0x0, information:0x1, attribs:0x0, share:0x
7, disposition:0x1, options:0x64, path:"C:\Users\i92segoa\Documents\desktop.ini"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryInformationFile, status:
0x0, iostatus:0x0, information:0x18, length:0x18, class:0x5, handle:0x544, path:
"C:\Users\i92segoa\Documents\desktop.ini"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies\Microsof
t\Windows\CurrentVersion\Internet Settings\Zones\3"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtReadFile, status:0x0, iostatu
s:0x0, information:0x192, length:0x194, handle:0x544, path:"C:\Users\i92segoa\Do
cuments\desktop.ini"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryInformationFile, status:
0x0, iostatus:0x0, information:0x28, length:0x28, class:0x4, handle:0x544, path:
"C:\Users\i92segoa\Documents\desktop.ini"

pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034


, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Se
ttings\Zones\3"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
44
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies\Microsof
t\Windows\CurrentVersion\Internet Settings\Zones\3"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x548, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x544, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\Curre
ntVersion\Explorer\FolderDescriptions"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Flags", class:0x2, length:0x90, resultlength:0x10, handle:0x548, path:"\REGI
STRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Wind
ows\CurrentVersion\Internet Settings\Zones\3"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x530, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\W
indows\CurrentVersion\Explorer\FolderDescriptions\{A0C69A99-21C8-4671-8703-79341
62FCF1D}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
48
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
44
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
40
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Category", class:0x2, length:0x90, resultlength:0x10, handle:0x530, path:"\R
EGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\F
olderDescriptions\{A0C69A99-21C8-4671-8703-7934162FCF1D}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x4, class:0x0, length:0x120, resultlength:0x12, handle:0x52C, path:"\REGISTR
Y\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Windows
\CurrentVersion\Internet Settings\Zones"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Name", class:0x2, length:0x90, resultlength:0x24, handle:0x530, path:"\REGIS
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Folde
rDescriptions\{A0C69A99-21C8-4671-8703-7934162FCF1D}"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"ParentFolder", class:0x2, length:0x90, resultlength:0x10, handle:0x5
30, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersio
n\Explorer\FolderDescriptions\{A0C69A99-21C8-4671-8703-7934162FCF1D}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x540, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Description", class:0x2, length:0x90, resultlength:0x10, handle:0x53
0, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion
\Explorer\FolderDescriptions\{A0C69A99-21C8-4671-8703-7934162FCF1D}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies\Microsof
t\Windows\CurrentVersion\Internet Settings\Zones\4"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"RelativePath", class:0x2, length:0x90, resultlength:0x18, handle:0x530, path
:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explor
er\FolderDescriptions\{A0C69A99-21C8-4671-8703-7934162FCF1D}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034

, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339


7-2463990887-1001\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Se
ttings\Zones\4"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0x8000
0005, name:"ParsingName", class:0x2, length:0x90, resultlength:0xBC, handle:0x53
0, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion
\Explorer\FolderDescriptions\{A0C69A99-21C8-4671-8703-7934162FCF1D}"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ParsingName", class:0x2, length:0xBC, resultlength:0xBC, handle:0x530, path:
"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explore
r\FolderDescriptions\{A0C69A99-21C8-4671-8703-7934162FCF1D}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies\Microsof
t\Windows\CurrentVersion\Internet Settings\Zones\4"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"InfoTip", class:0x2, length:0x90, resultlength:0x60, handle:0x530, path:"\RE
GISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Fo
lderDescriptions\{A0C69A99-21C8-4671-8703-7934162FCF1D}"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"LocalizedName", class:0x2, length:0x90, resultlength:0x60, handle:0x530, pat
h:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explo
rer\FolderDescriptions\{A0C69A99-21C8-4671-8703-7934162FCF1D}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x548, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Icon", class:0x2, length:0x90, resultlength:0x5C, handle:0x530, path:"\REGIS
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Folde
rDescriptions\{A0C69A99-21C8-4671-8703-7934162FCF1D}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Flags", class:0x2, length:0x90, resultlength:0x10, handle:0x548, path:"\REGI
STRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Wind
ows\CurrentVersion\Internet Settings\Zones\4"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
48
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Security", class:0x2, length:0x90, resultlength:0x5C, handle:0x530,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Ex
plorer\FolderDescriptions\{A0C69A99-21C8-4671-8703-7934162FCF1D}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
40
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"StreamResource", class:0x2, length:0x90, resultlength:0x5C, handle:0
x530, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVers
ion\Explorer\FolderDescriptions\{A0C69A99-21C8-4671-8703-7934162FCF1D}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtEnumerateKey, status:0x80000
01A, index:0x5, class:0x0, length:0x120, resultlength:0x0, handle:0x52C, path:"\
REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\
Windows\CurrentVersion\Internet Settings\Zones"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"StreamResourceType", class:0x2, length:0x90, resultlength:0x5C, hand
le:0x530, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Current
Version\Explorer\FolderDescriptions\{A0C69A99-21C8-4671-8703-7934162FCF1D}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
2C
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"LocalRedirectOnly", class:0x2, length:0x90, resultlength:0x5C, handl
e:0x530, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentV
ersion\Explorer\FolderDescriptions\{A0C69A99-21C8-4671-8703-7934162FCF1D}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034

, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24


63990887-1001\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_L
OCALMACHINE_LOCKDOWN"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Roamable", class:0x2, length:0x90, resultlength:0x5C, handle:0x530,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Ex
plorer\FolderDescriptions\{A0C69A99-21C8-4671-8703-7934162FCF1D}"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"PreCreate", class:0x2, length:0x90, resultlength:0x10, handle:0x530, path:"\
REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\
FolderDescriptions\{A0C69A99-21C8-4671-8703-7934162FCF1D}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x52C, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Inter
net Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Stream", class:0x2, length:0x90, resultlength:0x10, handle:0x530, pa
th:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Expl
orer\FolderDescriptions\{A0C69A99-21C8-4671-8703-7934162FCF1D}"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"PublishExpandedPath", class:0x2, length:0x90, resultlength:0x10, han
dle:0x530, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Curren
tVersion\Explorer\FolderDescriptions\{A0C69A99-21C8-4671-8703-7934162FCF1D}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"firefox.exe", class:0x2, length:0x90, resultlength:0xAA1199, handle:
0x52C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\
Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DefinitionFlags", class:0x2, length:0x90, resultlength:0x10, handle:
0x530, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVer
sion\Explorer\FolderDescriptions\{A0C69A99-21C8-4671-8703-7934162FCF1D}"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Attributes", class:0x2, length:0x90, resultlength:0x10, handle:0x530, path:"
\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer
\FolderDescriptions\{A0C69A99-21C8-4671-8703-7934162FCF1D}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"*", class:0x2, length:0x90, resultlength:0xAA1199, handle:0x52C, pat
h:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\Featu
reControl\FEATURE_LOCALMACHINE_LOCKDOWN"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
2C
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"FolderTypeID", class:0x2, length:0x90, resultlength:0x10, handle:0x5
30, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersio
n\Explorer\FolderDescriptions\{A0C69A99-21C8-4671-8703-7934162FCF1D}"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"InitFolderHandler", class:0x2, length:0x90, resultlength:0x10, handl
e:0x530, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentV
ersion\Explorer\FolderDescriptions\{A0C69A99-21C8-4671-8703-7934162FCF1D}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies\Microsof
t\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x544, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\W
indows\CurrentVersion\Explorer\FolderDescriptions\{A0C69A99-21C8-4671-8703-79341
62FCF1D}\PropertyBag"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Se
ttings\Lockdown_Zones\"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5

30
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x530, c
lass:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies\Microsof
t\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x538, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24639908
87-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Se
ttings\Lockdown_Zones\"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\K
nownFolders"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
38
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies\Microsof
t\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x52C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown
_Zones\"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x0, class:0x0, length:0x120, resultlength:0x12, handle:0x52C, path:"\REGISTR
Y\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Windows
\CurrentVersion\Internet Settings\Lockdown_Zones"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x53C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246399
0887-1001"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtCreateMutant, status:0x400000
00, handle:0x540, access:0x1F0001, owner:0x0, path:"\Sessions\1\BaseNamedObjects
\Local\ZonesLockedCacheCounterMutex"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x550, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folder
s"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x548, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown
_Zones\0"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
3C
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies\Microsof
t\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"{A0C69A99-21C8-4671-8703-7934162FCF1D}", class:0x2, length:0x90, res
ultlength:0x0, handle:0x550, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397
-2463990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell F
olders"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:New_NtQueryInformationToken::<l

ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x538, c


lass:0x1, length:0x40, returnlength:0x24, sid:"S-1-5-21-2360094602-2602383397-24
63990887-1001", attributes:0x0
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Se
ttings\Lockdown_Zones\0"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies\Microsof
t\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x53C, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows NT\Cu
rrentVersion\ProfileList\S-1-5-21-2360094602-2602383397-2463990887-1001"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ProfileImagePath", class:0x2, length:0x90, resultlength:0x30, handle:0x53C,
path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\ProfileList
\S-1-5-21-2360094602-2602383397-2463990887-1001"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x554, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ProfileImagePath", class:0x2, length:0x90, resultlength:0x30, handle:0x53C,
path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\ProfileList
\S-1-5-21-2360094602-2602383397-2463990887-1001"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
3C
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Flags", class:0x2, length:0x90, resultlength:0x10, handle:0x554, path:"\REGI
STRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Wind
ows\CurrentVersion\Internet Settings\Zones\0"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
38
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
54
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
30
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
48
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
50
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1, class:0x0, length:0x120, resultlength:0x12, handle:0x52C, path:"\REGISTR
Y\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Windows
\CurrentVersion\Internet Settings\Lockdown_Zones"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x548, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown
_Zones\1"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x3760000, zerobits:0x0, commitsize:0x0, offset:0x1E0000, viewsize:0x10
000, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5A0000
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies\Microsof
t\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5A0000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtUnmapViewOfSection, status:0x

0, address:0x3760000
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Se
ttings\Lockdown_Zones\1"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x3760000, zerobits:0x0, commitsize:0x0, offset:0x1E0000, viewsize:0x10
000, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5A0000
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies\Microsof
t\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5A0000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x3760000
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x554, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Flags", class:0x2, length:0x90, resultlength:0x10, handle:0x554, path:"\REGI
STRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Wind
ows\CurrentVersion\Internet Settings\Zones\1"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x558, access:0x2001F, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\
"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtSetValueKey, status:0x0, name
:"ProxyBypass", index:0x0, type:0x4, size:0x4, handle:0x558, path:"\REGISTRY\USE
R\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Windows\Curr
entVersion\Internet Settings\ZoneMap"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtCreateFile, status:0x0, handl
e:0x550, access:0x80100080, iostatus:0x0, information:0x1, attribs:0x0, share:0x
7, disposition:0x1, options:0x64, path:"C:\Users\i92segoa\Music\desktop.ini"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryInformationFile, status:
0x0, iostatus:0x0, information:0x18, length:0x18, class:0x5, handle:0x550, path:
"C:\Users\i92segoa\Music\desktop.ini"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtSetValueKey, status:0x0, name
:"IntranetName", index:0x0, type:0x4, size:0x4, handle:0x558, path:"\REGISTRY\US
ER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Windows\Cur
rentVersion\Internet Settings\ZoneMap"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtReadFile, status:0x0, iostatu
s:0x0, information:0x1F8, length:0x1FA, handle:0x550, path:"C:\Users\i92segoa\Mu
sic\desktop.ini"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtSetValueKey, status:0x0, name
:"UNCAsIntranet", index:0x0, type:0x4, size:0x4, handle:0x558, path:"\REGISTRY\U
SER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Windows\Cu
rrentVersion\Internet Settings\ZoneMap"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryInformationFile, status:
0x0, iostatus:0x0, information:0x28, length:0x28, class:0x4, handle:0x550, path:
"C:\Users\i92segoa\Music\desktop.ini"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
50
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtSetValueKey, status:0x0, name
:"AutoDetect", index:0x0, type:0x4, size:0x4, handle:0x558, path:"\REGISTRY\USER
\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Windows\Curre
ntVersion\Internet Settings\ZoneMap"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5

58
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
54
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
48
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x2, class:0x0, length:0x120, resultlength:0x12, handle:0x52C, path:"\REGISTR
Y\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Windows
\CurrentVersion\Internet Settings\Lockdown_Zones"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x550, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\Curre
ntVersion\Explorer\FolderDescriptions"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x530, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\W
indows\CurrentVersion\Explorer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F5971
3854639}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x548, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown
_Zones\2"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
50
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Category", class:0x2, length:0x90, resultlength:0x10, handle:0x530, path:"\R
EGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\F
olderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies\Microsof
t\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Name", class:0x2, length:0x90, resultlength:0x2A, handle:0x530, path:"\REGIS
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Folde
rDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"ParentFolder", class:0x2, length:0x90, resultlength:0x10, handle:0x5
30, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersio
n\Explorer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Se
ttings\Lockdown_Zones\2"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Description", class:0x2, length:0x90, resultlength:0x10, handle:0x53
0, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion
\Explorer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"RelativePath", class:0x2, length:0x90, resultlength:0x1E, handle:0x530, path
:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explor
er\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies\Microsof
t\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0x8000
0005, name:"ParsingName", class:0x2, length:0x90, resultlength:0xBC, handle:0x53
0, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion
\Explorer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ParsingName", class:0x2, length:0xBC, resultlength:0xBC, handle:0x530, path:
"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explore
r\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}"

pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle


:0x554, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"InfoTip", class:0x2, length:0x90, resultlength:0x60, handle:0x530, path:"\RE
GISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Fo
lderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Flags", class:0x2, length:0x90, resultlength:0x10, handle:0x554, path:"\REGI
STRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Wind
ows\CurrentVersion\Internet Settings\Zones\2"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
54
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"LocalizedName", class:0x2, length:0x90, resultlength:0x60, handle:0x530, pat
h:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explo
rer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
48
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Icon", class:0x2, length:0x90, resultlength:0x5C, handle:0x530, path:"\REGIS
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Folde
rDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x3, class:0x0, length:0x120, resultlength:0x12, handle:0x52C, path:"\REGISTR
Y\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Windows
\CurrentVersion\Internet Settings\Lockdown_Zones"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Security", class:0x2, length:0x90, resultlength:0x5C, handle:0x530,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Ex
plorer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"StreamResource", class:0x2, length:0x90, resultlength:0x5C, handle:0
x530, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVers
ion\Explorer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x548, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown
_Zones\3"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"StreamResourceType", class:0x2, length:0x90, resultlength:0x5C, hand
le:0x530, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Current
Version\Explorer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"LocalRedirectOnly", class:0x2, length:0x90, resultlength:0x5C, handl
e:0x530, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentV
ersion\Explorer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies\Microsof
t\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Roamable", class:0x2, length:0x90, resultlength:0x5C, handle:0x530,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Ex
plorer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"PreCreate", class:0x2, length:0x90, resultlength:0x10, handle:0x530, path:"\
REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\
FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339

7-2463990887-1001\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Se
ttings\Lockdown_Zones\3"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Stream", class:0x2, length:0x90, resultlength:0x10, handle:0x530, pa
th:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Expl
orer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"PublishExpandedPath", class:0x2, length:0x90, resultlength:0x10, han
dle:0x530, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Curren
tVersion\Explorer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies\Microsof
t\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DefinitionFlags", class:0x2, length:0x90, resultlength:0x10, handle:
0x530, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVer
sion\Explorer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Attributes", class:0x2, length:0x90, resultlength:0x10, handle:0x530, path:"
\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer
\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x554, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"FolderTypeID", class:0x2, length:0x90, resultlength:0x10, handle:0x5
30, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersio
n\Explorer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Flags", class:0x2, length:0x90, resultlength:0x10, handle:0x554, path:"\REGI
STRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Wind
ows\CurrentVersion\Internet Settings\Zones\3"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
54
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"InitFolderHandler", class:0x2, length:0x90, resultlength:0x10, handl
e:0x530, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentV
ersion\Explorer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
48
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x550, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\W
indows\CurrentVersion\Explorer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F5971
3854639}\PropertyBag"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x4, class:0x0, length:0x120, resultlength:0x12, handle:0x52C, path:"\REGISTR
Y\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Windows
\CurrentVersion\Internet Settings\Lockdown_Zones"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
30
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x530, c
lass:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x548, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown
_Zones\4"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x538, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24639908
87-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1"

pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034


, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies\Microsof
t\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\K
nownFolders"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
38
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Se
ttings\Lockdown_Zones\4"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies\Microsof
t\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x53C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246399
0887-1001"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x54C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folder
s"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
3C
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x464, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"{0DDD015D-B06C-45D5-8C4C-F59713854639}", class:0x2, length:0x90, res
ultlength:0x0, handle:0x54C, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397
-2463990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell F
olders"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Flags", class:0x2, length:0x90, resultlength:0x10, handle:0x464, path:"\REGI
STRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Wind
ows\CurrentVersion\Internet Settings\Zones\4"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x4
64
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x538, c
lass:0x1, length:0x40, returnlength:0x24, sid:"S-1-5-21-2360094602-2602383397-24
63990887-1001", attributes:0x0
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
48
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtEnumerateKey, status:0x80000
01A, index:0x5, class:0x0, length:0x120, resultlength:0x0, handle:0x52C, path:"\
REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\
Windows\CurrentVersion\Internet Settings\Lockdown_Zones"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
2C
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x53C, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows NT\Cu
rrentVersion\ProfileList\S-1-5-21-2360094602-2602383397-2463990887-1001"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ProfileImagePath", class:0x2, length:0x90, resultlength:0x30, handle:0x53C,

path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\ProfileList
\S-1-5-21-2360094602-2602383397-2463990887-1001"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"CreateUriCacheSize", class:0x2, length:0x90, resultlength:0x680000,
handle:0x3E4, path:"\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\Curren
tVersion\Internet Settings"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ProfileImagePath", class:0x2, length:0x90, resultlength:0x30, handle:0x53C,
path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\ProfileList
\S-1-5-21-2360094602-2602383397-2463990887-1001"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
3C
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"CreateUriCacheSize", class:0x2, length:0x90, resultlength:0x680000,
handle:0x3A8, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-100
1\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
38
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
30
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"CreateUriCacheSize", class:0x2, length:0x90, resultlength:0x680000,
handle:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-100
1\Software\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
4C
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"CreateUriCacheSize", class:0x2, length:0x90, resultlength:0x680000,
handle:0x3F4, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Cur
rentVersion\Internet Settings"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"EnablePunycode", class:0x2, length:0x90, resultlength:0x1264920, han
dle:0x3E4, path:"\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVe
rsion\Internet Settings"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x3760000, zerobits:0x0, commitsize:0x0, offset:0x1E0000, viewsize:0x10
000, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"EnablePunycode", class:0x2, length:0x90, resultlength:0x1264920, han
dle:0x3A8, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\S
OFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5A0000
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"EnablePunycode", class:0x2, length:0x90, resultlength:0x1264920, han
dle:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\S
oftware\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5A0000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"EnablePunycode", class:0x2, length:0x90, resultlength:0x10, handle:0x3F4, pa
th:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Inte
rnet Settings"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x3760000
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_A
LLOW_REVERSE_SOLIDUS_IN_USERINFO_KB932562"

pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtMapViewOfSection, status:0x0,


address:0x3760000, zerobits:0x0, commitsize:0x0, offset:0x1E0000, viewsize:0x10
000, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft
\Internet Explorer\Main\FeatureControl\FEATURE_ALLOW_REVERSE_SOLIDUS_IN_USERINFO
_KB932562"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5A0000
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5A0000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x3760000
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_U
SE_IETLDLIST_FOR_DOMAIN_DETERMINATION"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft
\Internet Explorer\Main\FeatureControl\FEATURE_USE_IETLDLIST_FOR_DOMAIN_DETERMIN
ATION"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtCreateFile, status:0x0, handl
e:0x54C, access:0x80100080, iostatus:0x0, information:0x1, attribs:0x0, share:0x
7, disposition:0x1, options:0x64, path:"C:\Users\i92segoa\Pictures\desktop.ini"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x548, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Internet Explorer\Security"
pid:4092, tid:8264, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x514, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Internet Explorer\Security"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryInformationFile, status:
0x0, iostatus:0x0, information:0x18, length:0x18, class:0x5, handle:0x54C, path:
"C:\Users\i92segoa\Pictures\desktop.ini"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DisableSecuritySettingsCheck", class:0x2, length:0x90, resultlength:
0x0, handle:0x548, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246399088
7-1001\SOFTWARE\Microsoft\Internet Explorer\Security"
pid:4092, tid:8264, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DisableSecuritySettingsCheck", class:0x2, length:0x90, resultlength:
0x0, handle:0x514, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246399088
7-1001\SOFTWARE\Microsoft\Internet Explorer\Security"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtReadFile, status:0x0, iostatu
s:0x0, information:0x1F8, length:0x1FA, handle:0x54C, path:"C:\Users\i92segoa\Pi
ctures\desktop.ini"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
48
pid:4092, tid:8264, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
14
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryInformationFile, status:
0x0, iostatus:0x0, information:0x28, length:0x28, class:0x4, handle:0x54C, path:
"C:\Users\i92segoa\Pictures\desktop.ini"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x548, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Internet Expl
orer\Security"
pid:4092, tid:8264, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x514, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Internet Expl
orer\Security"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
4C

pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000


0034, name:"DisableSecuritySettingsCheck", class:0x2, length:0x90, resultlength:
0x0, handle:0x548, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Intern
et Explorer\Security"
pid:4092, tid:8264, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DisableSecuritySettingsCheck", class:0x2, length:0x90, resultlength:
0x0, handle:0x514, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Intern
et Explorer\Security"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
48
pid:4092, tid:8264, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
14
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x54C, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\Curre
ntVersion\Explorer\FolderDescriptions"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x530, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\W
indows\CurrentVersion\Explorer\FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE7
3D76C95}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"WININET.dll", handle:0x701C0000
pid:4092, tid:8264, tick:0x33D700F, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"WININET.dll", handle:0x701C0000
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
4C
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x701C0000, name:"InternetInitializeAutoProxyDll", ordinal:
0x0, address:0x702D5790, image:0x0, caller:0x735747A8
pid:4092, tid:8264, tick:0x33D700F, lvl:OK, func:LdrUnloadDll, status:0x0, handl
e:0x701C0000
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Category", class:0x2, length:0x90, resultlength:0x10, handle:0x530, path:"\R
EGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\F
olderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}"
pid:4092, tid:8264, tick:0x33D700F, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x701C0000, name:"InternetInitializeAutoProxyDll", ordinal:
0x0, address:0x702D5790, image:0x0, caller:0x735747A8
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x754E0000, ordinal:0x4, address:0x754FAAD0, image:0x0, cal
ler:0x72A4ABED
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Name", class:0x2, length:0x90, resultlength:0x26, handle:0x530, path:"\REGIS
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Folde
rDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"OLEAUT32.dll", handle:0x754E0000
pid:4092, tid:8264, tick:0x33D700F, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"OLEAUT32.dll", handle:0x754E0000
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x754E0000, ordinal:0x7, address:0x754F2860, image:0x0, cal
ler:0x735747A8
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"ParentFolder", class:0x2, length:0x90, resultlength:0x10, handle:0x5
30, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersio
n\Explorer\FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}"
pid:4092, tid:8264, tick:0x33D700F, lvl:OK, func:LdrUnloadDll, status:0x0, handl
e:0x754E0000
pid:4092, tid:8264, tick:0x33D700F, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x754E0000, ordinal:0x7, address:0x754F2860, image:0x0, cal
ler:0x735747A8

pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000


0034, name:"Description", class:0x2, length:0x90, resultlength:0x10, handle:0x53
0, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion
\Explorer\FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x548, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\
Domains\"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"RelativePath", class:0x2, length:0x90, resultlength:0x1A, handle:0x530, path
:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explor
er\FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtQueryKey, status:0x0, class:0
x4, length:0xB0, resultlength:0x28, handle:0x548, path:"\REGISTRY\USER\S-1-5-212360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\
Internet Settings\ZoneMap\Domains"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0x8000
0005, name:"ParsingName", class:0x2, length:0x90, resultlength:0xBC, handle:0x53
0, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion
\Explorer\FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
48
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ParsingName", class:0x2, length:0xBC, resultlength:0xBC, handle:0x530, path:
"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explore
r\FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"InfoTip", class:0x2, length:0x90, resultlength:0x60, handle:0x530, path:"\RE
GISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Fo
lderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows
\CurrentVersion\Internet Settings\ZoneMap\Domains\"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"LocalizedName", class:0x2, length:0x90, resultlength:0x60, handle:0x530, pat
h:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explo
rer\FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"AutoDetect", class:0x2, length:0x90, resultlength:0x10, handle:0x520, path:"
\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft
\Windows\CurrentVersion\Internet Settings\ZoneMap"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Icon", class:0x2, length:0x90, resultlength:0x5C, handle:0x530, path:"\REGIS
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Folde
rDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}"
pid:4092, tid:8264, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x514, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\
Domains\"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"IntranetName", class:0x2, length:0x90, resultlength:0x10, handle:0x520, path
:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microso
ft\Windows\CurrentVersion\Internet Settings\ZoneMap"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Security", class:0x2, length:0x90, resultlength:0x5C, handle:0x530,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Ex
plorer\FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}"
pid:4092, tid:8264, tick:0x33D700F, lvl:OK, func:NtQueryKey, status:0x0, class:0
x4, length:0xB0, resultlength:0x28, handle:0x514, path:"\REGISTRY\USER\S-1-5-212360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\

Internet Settings\ZoneMap\Domains"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ProxyBypass", class:0x2, length:0x90, resultlength:0x10, handle:0x520, path:
"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsof
t\Windows\CurrentVersion\Internet Settings\ZoneMap"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"StreamResource", class:0x2, length:0x90, resultlength:0x5C, handle:0
x530, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVers
ion\Explorer\FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}"
pid:4092, tid:8264, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
14
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x701C0000, name:"IsHostInProxyBypassList", ordinal:0x0, ad
dress:0x702C22D0, image:0x0, caller:0x735747A8
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"StreamResourceType", class:0x2, length:0x90, resultlength:0x5C, hand
le:0x530, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Current
Version\Explorer\FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"LocalRedirectOnly", class:0x2, length:0x90, resultlength:0x5C, handl
e:0x530, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentV
ersion\Explorer\FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}"
pid:4092, tid:8264, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows
\CurrentVersion\Internet Settings\ZoneMap\Domains\"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
48
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Roamable", class:0x2, length:0x90, resultlength:0x5C, handle:0x530,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Ex
plorer\FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}"
pid:4092, tid:8264, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"AutoDetect", class:0x2, length:0x90, resultlength:0x10, handle:0x520, path:"
\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft
\Windows\CurrentVersion\Internet Settings\ZoneMap"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"PreCreate", class:0x2, length:0x90, resultlength:0x10, handle:0x530, path:"\
REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\
FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x548, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\
ProtocolDefaults\"
pid:4092, tid:8264, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"IntranetName", class:0x2, length:0x90, resultlength:0x10, handle:0x520, path
:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microso
ft\Windows\CurrentVersion\Internet Settings\ZoneMap"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Stream", class:0x2, length:0x90, resultlength:0x10, handle:0x530, pa
th:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Expl
orer\FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtQueryKey, status:0x0, class:0
x4, length:0xB0, resultlength:0x28, handle:0x548, path:"\REGISTRY\USER\S-1-5-212360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\
Internet Settings\ZoneMap\ProtocolDefaults"
pid:4092, tid:8264, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ProxyBypass", class:0x2, length:0x90, resultlength:0x10, handle:0x520, path:
"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsof
t\Windows\CurrentVersion\Internet Settings\ZoneMap"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000

0034, name:"PublishExpandedPath", class:0x2, length:0x90, resultlength:0x10, han


dle:0x530, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Curren
tVersion\Explorer\FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtEnumerateValueKey, status:0x0
, index:0x0, class:0x1, length:0xDC, resultlength:0x1A, handle:0x548, path:"\REG
ISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Win
dows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults"
pid:4092, tid:8264, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
14
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DefinitionFlags", class:0x2, length:0x90, resultlength:0x10, handle:
0x530, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVer
sion\Explorer\FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtEnumerateValueKey, status:0x0
, index:0x1, class:0x1, length:0xDC, resultlength:0x24, handle:0x548, path:"\REG
ISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Win
dows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Attributes", class:0x2, length:0x90, resultlength:0x10, handle:0x530, path:"
\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer
\FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtEnumerateValueKey, status:0x0
, index:0x2, class:0x1, length:0xDC, resultlength:0x24, handle:0x548, path:"\REG
ISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Win
dows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"FolderTypeID", class:0x2, length:0x90, resultlength:0x10, handle:0x5
30, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersio
n\Explorer\FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtEnumerateValueKey, status:0x0
, index:0x3, class:0x1, length:0xDC, resultlength:0x24, handle:0x548, path:"\REG
ISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Win
dows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"InitFolderHandler", class:0x2, length:0x90, resultlength:0x10, handl
e:0x530, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentV
ersion\Explorer\FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtEnumerateValueKey, status:0x0
, index:0x4, class:0x1, length:0xDC, resultlength:0x24, handle:0x548, path:"\REG
ISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Win
dows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtEnumerateValueKey, status:0x0
, index:0x5, class:0x1, length:0xDC, resultlength:0x24, handle:0x548, path:"\REG
ISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Win
dows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x54C, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\W
indows\CurrentVersion\Explorer\FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE7
3D76C95}\PropertyBag"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
30
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtEnumerateValueKey, status:0x0
, index:0x6, class:0x1, length:0xDC, resultlength:0x24, handle:0x548, path:"\REG
ISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Win
dows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x530, c
lass:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtEnumerateValueKey, status:0x0
, index:0x7, class:0x1, length:0xDC, resultlength:0x34, handle:0x548, path:"\REG

ISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Win
dows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
48
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x754E0000, ordinal:0x6, address:0x754FAC10, image:0x0, cal
ler:0x735747A8
pid:4092, tid:8264, tick:0x33D700F, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x754E0000, ordinal:0x6, address:0x754FAC10, image:0x0, cal
ler:0x735747A8
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x538, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24639908
87-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\K
nownFolders"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
38
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x548, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"1A10", class:0x2, length:0x90, resultlength:0x331F654, handle:0x548,
path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Mi
crosoft\Windows\CurrentVersion\Internet Settings\Zones\3"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x464, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\Curre
ntVersion\Internet Settings\Zones\3"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x53C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246399
0887-1001"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"1A10", class:0x2, length:0x90, resultlength:0x10, handle:0x464, path:"\REGIS
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Internet Setti
ngs\Zones\3"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
48
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x4
64
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x52C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folder
s"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
3C
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"{35286A68-3C57-41A1-BBB1-0EAE73D76C95}", class:0x2, length:0x90, res
ultlength:0x0, handle:0x52C, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397
-2463990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell F
olders"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x538, c
lass:0x1, length:0x40, returnlength:0x24, sid:"S-1-5-21-2360094602-2602383397-24
63990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle

:0x53C, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows NT\Cu


rrentVersion\ProfileList\S-1-5-21-2360094602-2602383397-2463990887-1001"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x464, access:0xF, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24639908
87-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ProfileImagePath", class:0x2, length:0x90, resultlength:0x30, handle:0x53C,
path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\ProfileList
\S-1-5-21-2360094602-2602383397-2463990887-1001"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ProfileImagePath", class:0x2, length:0x90, resultlength:0x30, handle:0x53C,
path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\ProfileList
\S-1-5-21-2360094602-2602383397-2463990887-1001"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
3C
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
38
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
30
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
2C
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtCreateFile, status:0xC000003
5, handle:0x0, access:0x100001, iostatus:0x43005C, information:0x720075, attribs
:0x80, share:0x3, disposition:0x2, options:0x204021, path:"C:\Users\i92segoa"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x3760000, zerobits:0x0, commitsize:0x0, offset:0x210000, viewsize:0x10
000, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5A0000
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5A0000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x3760000
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x3760000, zerobits:0x0, commitsize:0x0, offset:0x210000, viewsize:0x10
000, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5A0000
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5A0000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x3760000
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x10, path:"C:\Users\i92segoa"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtCreateFile, status:0x0, handl
e:0x52C, access:0x80100080, iostatus:0x0, information:0x1, attribs:0x0, share:0x
7, disposition:0x1, options:0x64, path:"C:\Users\i92segoa\Videos\desktop.ini"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryInformationFile, status:
0x0, iostatus:0x0, information:0x18, length:0x18, class:0x5, handle:0x52C, path:
"C:\Users\i92segoa\Videos\desktop.ini"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtReadFile, status:0x0, iostatu
s:0x0, information:0x1F8, length:0x1FA, handle:0x52C, path:"C:\Users\i92segoa\Vi
deos\desktop.ini"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryInformationFile, status:
0x0, iostatus:0x0, information:0x28, length:0x28, class:0x4, handle:0x52C, path:
"C:\Users\i92segoa\Videos\desktop.ini"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
2C

pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtCreateFile, status:0xC000003


5, handle:0x0, access:0x100001, iostatus:0x0, information:0xFFFFFFFF, attribs:0x
80, share:0x3, disposition:0x2, options:0x204021, path:"C:\Users\i92segoa\AppDat
a\Local"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x52C, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\Curre
ntVersion\Explorer\FolderDescriptions"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x530, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\W
indows\CurrentVersion\Explorer\FolderDescriptions\{7D83EE9B-2244-4E70-B1F5-53930
42AF1E4}"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
2C
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Category", class:0x2, length:0x90, resultlength:0x10, handle:0x530, path:"\R
EGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\F
olderDescriptions\{7D83EE9B-2244-4E70-B1F5-5393042AF1E4}"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Name", class:0x2, length:0x90, resultlength:0x2C, handle:0x530, path:"\REGIS
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Folde
rDescriptions\{7D83EE9B-2244-4E70-B1F5-5393042AF1E4}"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"ParentFolder", class:0x2, length:0x90, resultlength:0x10, handle:0x5
30, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersio
n\Explorer\FolderDescriptions\{7D83EE9B-2244-4E70-B1F5-5393042AF1E4}"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Description", class:0x2, length:0x90, resultlength:0x10, handle:0x53
0, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion
\Explorer\FolderDescriptions\{7D83EE9B-2244-4E70-B1F5-5393042AF1E4}"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"RelativePath", class:0x2, length:0x90, resultlength:0x20, handle:0x530, path
:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explor
er\FolderDescriptions\{7D83EE9B-2244-4E70-B1F5-5393042AF1E4}"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0x8000
0005, name:"ParsingName", class:0x2, length:0x90, resultlength:0xBC, handle:0x53
0, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion
\Explorer\FolderDescriptions\{7D83EE9B-2244-4E70-B1F5-5393042AF1E4}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x10, path:"C:\Users\i92segoa\AppData\Local"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ParsingName", class:0x2, length:0xBC, resultlength:0xBC, handle:0x530, path:
"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explore
r\FolderDescriptions\{7D83EE9B-2244-4E70-B1F5-5393042AF1E4}"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"InfoTip", class:0x2, length:0x90, resultlength:0xBC, handle:0x530, p
ath:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Exp
lorer\FolderDescriptions\{7D83EE9B-2244-4E70-B1F5-5393042AF1E4}"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"LocalizedName", class:0x2, length:0x90, resultlength:0x60, handle:0x530, pat
h:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explo
rer\FolderDescriptions\{7D83EE9B-2244-4E70-B1F5-5393042AF1E4}"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Icon", class:0x2, length:0x90, resultlength:0x5C, handle:0x530, path:"\REGIS
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Folde
rDescriptions\{7D83EE9B-2244-4E70-B1F5-5393042AF1E4}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtCreateFile, status:0xC000003
5, handle:0x0, access:0x100001, iostatus:0x0, information:0xFFFFFFFF, attribs:0x
80, share:0x3, disposition:0x2, options:0x204021, path:"C:\Users\i92segoa\AppDat
a\Local\Microsoft\Windows\INetCache"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000

0034, name:"Security", class:0x2, length:0x90, resultlength:0x5C, handle:0x530,


path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Ex
plorer\FolderDescriptions\{7D83EE9B-2244-4E70-B1F5-5393042AF1E4}"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"StreamResource", class:0x2, length:0x90, resultlength:0x5C, handle:0
x530, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVers
ion\Explorer\FolderDescriptions\{7D83EE9B-2244-4E70-B1F5-5393042AF1E4}"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"StreamResourceType", class:0x2, length:0x90, resultlength:0x5C, hand
le:0x530, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Current
Version\Explorer\FolderDescriptions\{7D83EE9B-2244-4E70-B1F5-5393042AF1E4}"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"LocalRedirectOnly", class:0x2, length:0x90, resultlength:0x5C, handl
e:0x530, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentV
ersion\Explorer\FolderDescriptions\{7D83EE9B-2244-4E70-B1F5-5393042AF1E4}"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Roamable", class:0x2, length:0x90, resultlength:0x5C, handle:0x530,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Ex
plorer\FolderDescriptions\{7D83EE9B-2244-4E70-B1F5-5393042AF1E4}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x2016, path:"C:\Users\i92segoa\AppData\Local\Microsoft\Windows\INet
Cache"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtSetInformationProcess, status
:0x0, class:0xC, length:0x4
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"PreCreate", class:0x2, length:0x90, resultlength:0x10, handle:0x530, path:"\
REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\
FolderDescriptions\{7D83EE9B-2244-4E70-B1F5-5393042AF1E4}"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Stream", class:0x2, length:0x90, resultlength:0x10, handle:0x530, pa
th:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Expl
orer\FolderDescriptions\{7D83EE9B-2244-4E70-B1F5-5393042AF1E4}"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"PublishExpandedPath", class:0x2, length:0x90, resultlength:0x10, han
dle:0x530, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Curren
tVersion\Explorer\FolderDescriptions\{7D83EE9B-2244-4E70-B1F5-5393042AF1E4}"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DefinitionFlags", class:0x2, length:0x90, resultlength:0x10, handle:
0x530, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVer
sion\Explorer\FolderDescriptions\{7D83EE9B-2244-4E70-B1F5-5393042AF1E4}"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Attributes", class:0x2, length:0x90, resultlength:0x10, handle:0x530, path:"
\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer
\FolderDescriptions\{7D83EE9B-2244-4E70-B1F5-5393042AF1E4}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x10, path:"C:\Users\i92segoa\AppData\Local\Microsoft\Windows"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"FolderTypeID", class:0x2, length:0x90, resultlength:0x10, handle:0x5
30, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersio
n\Explorer\FolderDescriptions\{7D83EE9B-2244-4E70-B1F5-5393042AF1E4}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtSetInformationProcess, status
:0x0, class:0xC, length:0x4
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"InitFolderHandler", class:0x2, length:0x90, resultlength:0x10, handl
e:0x530, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentV
ersion\Explorer\FolderDescriptions\{7D83EE9B-2244-4E70-B1F5-5393042AF1E4}"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x52C, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\W
indows\CurrentVersion\Explorer\FolderDescriptions\{7D83EE9B-2244-4E70-B1F5-53930
42AF1E4}\PropertyBag"

pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5


30
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x530, c
lass:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x2416, path:"C:\Users\i92segoa\AppData\Local\Microsoft\Windows\INet
Cache\Content.IE5"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x538, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24639908
87-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\K
nownFolders"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
38
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x2016, path:"C:\Users\i92segoa\AppData\Local\Microsoft\Windows\INet
Cache\IE"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x53C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246399
0887-1001"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x554, access:0xF, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24639908
87-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Co
ntent"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x548, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folder
s"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtSetValueKey, status:0x0, name
:"CachePrefix", index:0x0, type:0x1, size:0x2, handle:0x554, path:"\REGISTRY\USE
R\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Windows\Curr
entVersion\Internet Settings\5.0\Cache\Content"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
3C
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"CacheLimit", class:0x2, length:0x90, resultlength:0x10, handle:0x554, path:"
\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft
\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"{7D83EE9B-2244-4E70-B1F5-5393042AF1E4}", class:0x2, length:0x90, res
ultlength:0x0, handle:0x548, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397
-2463990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell F
olders"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
54
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x554, c
lass:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x538, c
lass:0x1, length:0x40, returnlength:0x24, sid:"S-1-5-21-2360094602-2602383397-24
63990887-1001", attributes:0x0
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle

:0x558, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\Curre


ntVersion\Explorer\FolderDescriptions"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x53C, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows NT\Cu
rrentVersion\ProfileList\S-1-5-21-2360094602-2602383397-2463990887-1001"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ProfileImagePath", class:0x2, length:0x90, resultlength:0x30, handle:0x53C,
path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\ProfileList
\S-1-5-21-2360094602-2602383397-2463990887-1001"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x55C, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\W
indows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A61
1B84FF6}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
58
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ProfileImagePath", class:0x2, length:0x90, resultlength:0x30, handle:0x53C,
path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\ProfileList
\S-1-5-21-2360094602-2602383397-2463990887-1001"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
3C
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Category", class:0x2, length:0x90, resultlength:0x10, handle:0x55C, path:"\R
EGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\F
olderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
38
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
30
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Name", class:0x2, length:0x90, resultlength:0x1C, handle:0x55C, path:"\REGIS
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Folde
rDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
48
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ParentFolder", class:0x2, length:0x90, resultlength:0x5A, handle:0x55C, path
:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explor
er\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Description", class:0x2, length:0x90, resultlength:0x5A, handle:0x55
C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion
\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"RelativePath", class:0x2, length:0x90, resultlength:0x48, handle:0x55C, path
:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explor
er\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x3760000, zerobits:0x0, commitsize:0x0, offset:0x1E0000, viewsize:0x10
000, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"ParsingName", class:0x2, length:0x90, resultlength:0x48, handle:0x55
C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion
\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5A0000
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"InfoTip", class:0x2, length:0x90, resultlength:0x48, handle:0x55C, p
ath:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Exp
lorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}"

pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000


0034, name:"LocalizedName", class:0x2, length:0x90, resultlength:0x48, handle:0x
55C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersi
on\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Icon", class:0x2, length:0x90, resultlength:0x48, handle:0x55C, path
:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explor
er\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Security", class:0x2, length:0x90, resultlength:0x48, handle:0x55C,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Ex
plorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"StreamResource", class:0x2, length:0x90, resultlength:0x48, handle:0
x55C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVers
ion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"StreamResourceType", class:0x2, length:0x90, resultlength:0x48, hand
le:0x55C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Current
Version\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"LocalRedirectOnly", class:0x2, length:0x90, resultlength:0x48, handl
e:0x55C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentV
ersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtCreateFile, status:0x0, handl
e:0x548, access:0x80100080, iostatus:0x0, information:0x1, attribs:0x0, share:0x
7, disposition:0x1, options:0x64, path:"C:\Users\i92segoa\Downloads\desktop.ini"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryInformationFile, status:
0x0, iostatus:0x0, information:0x18, length:0x18, class:0x5, handle:0x548, path:
"C:\Users\i92segoa\Downloads\desktop.ini"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Roamable", class:0x2, length:0x90, resultlength:0x48, handle:0x55C,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Ex
plorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtReadFile, status:0x0, iostatu
s:0x0, information:0x11A, length:0x11C, handle:0x548, path:"C:\Users\i92segoa\Do
wnloads\desktop.ini"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"PreCreate", class:0x2, length:0x90, resultlength:0x48, handle:0x55C,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\E
xplorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryInformationFile, status:
0x0, iostatus:0x0, information:0x28, length:0x28, class:0x4, handle:0x548, path:
"C:\Users\i92segoa\Downloads\desktop.ini"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Stream", class:0x2, length:0x90, resultlength:0x48, handle:0x55C, pa
th:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Expl
orer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
48
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"PublishExpandedPath", class:0x2, length:0x90, resultlength:0x48, han
dle:0x55C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Curren
tVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DefinitionFlags", class:0x2, length:0x90, resultlength:0x48, handle:
0x55C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVer
sion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Attributes", class:0x2, length:0x90, resultlength:0x48, handle:0x55C

, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\
Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"FolderTypeID", class:0x2, length:0x90, resultlength:0x48, handle:0x5
5C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersio
n\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"InitFolderHandler", class:0x2, length:0x90, resultlength:0x48, handl
e:0x55C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentV
ersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Micro
soft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E
-08A611B84FF6}\PropertyBag"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
5C
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x55C, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24639908
87-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x548, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\Curre
ntVersion\Explorer\FolderDescriptions"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\K
nownFolders"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
5C
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x530, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\W
indows\CurrentVersion\Explorer\FolderDescriptions\{A52BBA46-E9E1-435F-B3D9-28DAA
648C0F6}"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
48
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Category", class:0x2, length:0x90, resultlength:0x10, handle:0x530, path:"\R
EGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\F
olderDescriptions\{A52BBA46-E9E1-435F-B3D9-28DAA648C0F6}"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Name", class:0x2, length:0x90, resultlength:0x1E, handle:0x530, path:"\REGIS
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Folde
rDescriptions\{A52BBA46-E9E1-435F-B3D9-28DAA648C0F6}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x558, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246399
0887-1001"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ParentFolder", class:0x2, length:0x90, resultlength:0x5A, handle:0x530, path
:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explor
er\FolderDescriptions\{A52BBA46-E9E1-435F-B3D9-28DAA648C0F6}"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Description", class:0x2, length:0x90, resultlength:0x5A, handle:0x53
0, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion
\Explorer\FolderDescriptions\{A52BBA46-E9E1-435F-B3D9-28DAA648C0F6}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x564, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folder

s"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"RelativePath", class:0x2, length:0x90, resultlength:0x1E, handle:0x530, path
:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explor
er\FolderDescriptions\{A52BBA46-E9E1-435F-B3D9-28DAA648C0F6}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
58
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ParsingName", class:0x2, length:0x90, resultlength:0x6A, handle:0x530, path:
"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explore
r\FolderDescriptions\{A52BBA46-E9E1-435F-B3D9-28DAA648C0F6}"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"InfoTip", class:0x2, length:0x90, resultlength:0x6A, handle:0x530, p
ath:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Exp
lorer\FolderDescriptions\{A52BBA46-E9E1-435F-B3D9-28DAA648C0F6}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Cookies", class:0x2, length:0x90, resultlength:0x88, handle:0x564, path:"\RE
GISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Wi
ndows\CurrentVersion\Explorer\User Shell Folders"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"LocalizedName", class:0x2, length:0x90, resultlength:0x6E, handle:0x530, pat
h:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explo
rer\FolderDescriptions\{A52BBA46-E9E1-435F-B3D9-28DAA648C0F6}"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Icon", class:0x2, length:0x90, resultlength:0x5E, handle:0x530, path:"\REGIS
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Folde
rDescriptions\{A52BBA46-E9E1-435F-B3D9-28DAA648C0F6}"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Security", class:0x2, length:0x90, resultlength:0x5E, handle:0x530,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Ex
plorer\FolderDescriptions\{A52BBA46-E9E1-435F-B3D9-28DAA648C0F6}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
54
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
64
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"StreamResource", class:0x2, length:0x90, resultlength:0x5E, handle:0
x530, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVers
ion\Explorer\FolderDescriptions\{A52BBA46-E9E1-435F-B3D9-28DAA648C0F6}"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"StreamResourceType", class:0x2, length:0x90, resultlength:0x5E, hand
le:0x530, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Current
Version\Explorer\FolderDescriptions\{A52BBA46-E9E1-435F-B3D9-28DAA648C0F6}"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"LocalRedirectOnly", class:0x2, length:0x90, resultlength:0x10, handle:0x530,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\E
xplorer\FolderDescriptions\{A52BBA46-E9E1-435F-B3D9-28DAA648C0F6}"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Roamable", class:0x2, length:0x90, resultlength:0x10, handle:0x530,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Ex
plorer\FolderDescriptions\{A52BBA46-E9E1-435F-B3D9-28DAA648C0F6}"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"PreCreate", class:0x2, length:0x90, resultlength:0x10, handle:0x530,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\E
xplorer\FolderDescriptions\{A52BBA46-E9E1-435F-B3D9-28DAA648C0F6}"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Stream", class:0x2, length:0x90, resultlength:0x10, handle:0x530, pa
th:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Expl
orer\FolderDescriptions\{A52BBA46-E9E1-435F-B3D9-28DAA648C0F6}"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000

0034, name:"PublishExpandedPath", class:0x2, length:0x90, resultlength:0x10, han


dle:0x530, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Curren
tVersion\Explorer\FolderDescriptions\{A52BBA46-E9E1-435F-B3D9-28DAA648C0F6}"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"DefinitionFlags", class:0x2, length:0x90, resultlength:0x10, handle:0x530, p
ath:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Exp
lorer\FolderDescriptions\{A52BBA46-E9E1-435F-B3D9-28DAA648C0F6}"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Attributes", class:0x2, length:0x90, resultlength:0x10, handle:0x530, path:"
\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer
\FolderDescriptions\{A52BBA46-E9E1-435F-B3D9-28DAA648C0F6}"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"FolderTypeID", class:0x2, length:0x90, resultlength:0x10, handle:0x5
30, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersio
n\Explorer\FolderDescriptions\{A52BBA46-E9E1-435F-B3D9-28DAA648C0F6}"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"InitFolderHandler", class:0x2, length:0x90, resultlength:0x10, handl
e:0x530, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentV
ersion\Explorer\FolderDescriptions\{A52BBA46-E9E1-435F-B3D9-28DAA648C0F6}"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Micro
soft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A52BBA46-E9E1-435F-B3D9
-28DAA648C0F6}\PropertyBag"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
30
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x530, c
lass:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x548, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24639908
87-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\K
nownFolders"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
48
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtCreateFile, status:0xC000003
5, handle:0x0, access:0x100001, iostatus:0x6F006C, information:0x650073, attribs
:0x80, share:0x3, disposition:0x2, options:0x204021, path:"C:\Users\i92segoa"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x538, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246399
0887-1001"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x53C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folder
s"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
38
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"{A52BBA46-E9E1-435F-B3D9-28DAA648C0F6}", class:0x2, length:0x90, res
ultlength:0x0, handle:0x53C, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397
-2463990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell F
olders"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x548, c

lass:0x1, length:0x40, returnlength:0x24, sid:"S-1-5-21-2360094602-2602383397-24


63990887-1001", attributes:0x0
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x10, path:"C:\Users\i92segoa"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x538, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows NT\Cu
rrentVersion\ProfileList\S-1-5-21-2360094602-2602383397-2463990887-1001"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ProfileImagePath", class:0x2, length:0x90, resultlength:0x30, handle:0x538,
path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\ProfileList
\S-1-5-21-2360094602-2602383397-2463990887-1001"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ProfileImagePath", class:0x2, length:0x90, resultlength:0x30, handle:0x538,
path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\ProfileList
\S-1-5-21-2360094602-2602383397-2463990887-1001"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
38
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
48
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
30
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
3C
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtCreateFile, status:0xC000003
5, handle:0x0, access:0x100001, iostatus:0x0, information:0xFFFFFFFF, attribs:0x
80, share:0x3, disposition:0x2, options:0x204021, path:"C:\Users\i92segoa\AppDat
a\Local"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtCreateFile, status:0x0, handl
e:0x53C, access:0x80100080, iostatus:0x0, information:0x1, attribs:0x0, share:0x
7, disposition:0x1, options:0x64, path:"C:\Users\i92segoa\OneDrive\desktop.ini"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryInformationFile, status:
0x0, iostatus:0x0, information:0x18, length:0x18, class:0x5, handle:0x53C, path:
"C:\Users\i92segoa\OneDrive\desktop.ini"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtReadFile, status:0x0, iostatu
s:0x0, information:0x63, length:0x65, handle:0x53C, path:"C:\Users\i92segoa\OneD
rive\desktop.ini"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryInformationFile, status:
0x0, iostatus:0x0, information:0x28, length:0x28, class:0x4, handle:0x53C, path:
"C:\Users\i92segoa\OneDrive\desktop.ini"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
3C
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x10, path:"C:\Users\i92segoa\AppData\Local"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x53C, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\Curre
ntVersion\Explorer\FolderDescriptions"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtCreateFile, status:0xC000003
5, handle:0x0, access:0x100001, iostatus:0x0, information:0xFFFFFFFF, attribs:0x
80, share:0x3, disposition:0x2, options:0x204021, path:"C:\Users\i92segoa\AppDat
a\Local\Microsoft\Windows\INetCookies"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x530, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\W
indows\CurrentVersion\Explorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08
E667CA7}"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
3C
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Category", class:0x2, length:0x90, resultlength:0x10, handle:0x530, path:"\R
EGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\F
olderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}"

pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na


me:"Name", class:0x2, length:0x90, resultlength:0x2E, handle:0x530, path:"\REGIS
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Folde
rDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"ParentFolder", class:0x2, length:0x90, resultlength:0x10, handle:0x5
30, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersio
n\Explorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x2036, path:"C:\Users\i92segoa\AppData\Local\Microsoft\Windows\INet
Cookies"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtSetInformationProcess, status
:0x0, class:0xC, length:0x4
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Description", class:0x2, length:0x90, resultlength:0x10, handle:0x53
0, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion
\Explorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"RelativePath", class:0x2, length:0x90, resultlength:0x10, handle:0x5
30, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersio
n\Explorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ParsingName", class:0x2, length:0x90, resultlength:0x5E, handle:0x530, path:
"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explore
r\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"InfoTip", class:0x2, length:0x90, resultlength:0x5E, handle:0x530, p
ath:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Exp
lorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"LocalizedName", class:0x2, length:0x90, resultlength:0x5E, handle:0x
530, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersi
on\Explorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x10, path:"C:\Users\i92segoa\AppData\Local\Microsoft\Windows"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtSetInformationProcess, status
:0x0, class:0xC, length:0x4
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Icon", class:0x2, length:0x90, resultlength:0x5E, handle:0x530, path
:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explor
er\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Security", class:0x2, length:0x90, resultlength:0x5E, handle:0x530,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Ex
plorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"StreamResource", class:0x2, length:0x90, resultlength:0x5E, handle:0
x530, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVers
ion\Explorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"StreamResourceType", class:0x2, length:0x90, resultlength:0x5E, hand
le:0x530, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Current
Version\Explorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"LocalRedirectOnly", class:0x2, length:0x90, resultlength:0x5E, handl
e:0x530, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentV
ersion\Explorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x2036, path:"C:\Users\i92segoa\AppData\Local\Microsoft\Windows\INet
Cookies"

pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000


0034, name:"Roamable", class:0x2, length:0x90, resultlength:0x5E, handle:0x530,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Ex
plorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"PreCreate", class:0x2, length:0x90, resultlength:0x5E, handle:0x530,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\E
xplorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x564, access:0xF, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24639908
87-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Co
okies"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Stream", class:0x2, length:0x90, resultlength:0x5E, handle:0x530, pa
th:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Expl
orer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"PublishExpandedPath", class:0x2, length:0x90, resultlength:0x5E, han
dle:0x530, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Curren
tVersion\Explorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtSetValueKey, status:0x0, name
:"CachePrefix", index:0x0, type:0x1, size:0x10, handle:0x564, path:"\REGISTRY\US
ER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Windows\Cur
rentVersion\Internet Settings\5.0\Cache\Cookies"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DefinitionFlags", class:0x2, length:0x90, resultlength:0x5E, handle:
0x530, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVer
sion\Explorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"CacheLimit", class:0x2, length:0x90, resultlength:0x10, handle:0x564, path:"
\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft
\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Attributes", class:0x2, length:0x90, resultlength:0x5E, handle:0x530
, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\
Explorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
64
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"FolderTypeID", class:0x2, length:0x90, resultlength:0x5E, handle:0x5
30, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersio
n\Explorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x564, c
lass:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"InitFolderHandler", class:0x2, length:0x90, resultlength:0x5E, handl
e:0x530, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentV
ersion\Explorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Micro
soft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D
-79D08E667CA7}\PropertyBag"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
30
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x554, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\Curre
ntVersion\Explorer\FolderDescriptions"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x55C, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\W

indows\CurrentVersion\Explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A113
0A75963}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
54
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Category", class:0x2, length:0x90, resultlength:0x10, handle:0x55C, path:"\R
EGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\F
olderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Name", class:0x2, length:0x90, resultlength:0x1C, handle:0x55C, path:"\REGIS
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Folde
rDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ParentFolder", class:0x2, length:0x90, resultlength:0x5A, handle:0x55C, path
:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explor
er\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Description", class:0x2, length:0x90, resultlength:0x5A, handle:0x55
C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion
\Explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"RelativePath", class:0x2, length:0x90, resultlength:0x40, handle:0x55C, path
:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explor
er\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"ParsingName", class:0x2, length:0x90, resultlength:0x40, handle:0x55
C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion
\Explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"InfoTip", class:0x2, length:0x90, resultlength:0x40, handle:0x55C, p
ath:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Exp
lorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"LocalizedName", class:0x2, length:0x90, resultlength:0x40, handle:0x
55C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersi
on\Explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Icon", class:0x2, length:0x90, resultlength:0x40, handle:0x55C, path
:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explor
er\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Security", class:0x2, length:0x90, resultlength:0x40, handle:0x55C,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Ex
plorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"StreamResource", class:0x2, length:0x90, resultlength:0x40, handle:0
x55C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVers
ion\Explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"StreamResourceType", class:0x2, length:0x90, resultlength:0x40, hand
le:0x55C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Current
Version\Explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"LocalRedirectOnly", class:0x2, length:0x90, resultlength:0x10, handle:0x55C,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\E
xplorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Roamable", class:0x2, length:0x90, resultlength:0x10, handle:0x55C,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Ex
plorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}"

pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000


0034, name:"PreCreate", class:0x2, length:0x90, resultlength:0x10, handle:0x55C,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\E
xplorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Stream", class:0x2, length:0x90, resultlength:0x10, handle:0x55C, pa
th:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Expl
orer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"PublishExpandedPath", class:0x2, length:0x90, resultlength:0x10, han
dle:0x55C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Curren
tVersion\Explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DefinitionFlags", class:0x2, length:0x90, resultlength:0x10, handle:
0x55C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVer
sion\Explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Attributes", class:0x2, length:0x90, resultlength:0x10, handle:0x55C
, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\
Explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"FolderTypeID", class:0x2, length:0x90, resultlength:0x10, handle:0x5
5C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersio
n\Explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"InitFolderHandler", class:0x2, length:0x90, resultlength:0x10, handl
e:0x55C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentV
ersion\Explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Micro
soft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781
-5A1130A75963}\PropertyBag"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
5C
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x55C, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24639908
87-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\K
nownFolders"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenFile, status:0x0, handle:
0x530, access:0x100080, iostatus:0x0, information:0x0, share:0x3, options:0x10,
path:"C:"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
5C
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, iostatus:0x0, information:0x30, code:0x4D0008, inlen:0x0, outlen:0x208, hand
le:0x530, path:"C:"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
30
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtCreateFile, status:0x0, handl
e:0x530, access:0x100080, iostatus:0x0, information:0x0, attribs:0x80, share:0x3
, disposition:0x1, options:0x60, path:"\??\MountPointManager"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x554, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246399

0887-1001"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtDeviceIoControlFile, status:
0x80000005, iostatus:0x80000005, information:0x8, code:0x6D0008, inlen:0x46, out
len:0x20, handle:0x530, path:"\??\MountPointManager"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, iostatus:0x0, information:0xFA, code:0x6D0008, inlen:0x46, outlen:0xFA, hand
le:0x530, path:"\??\MountPointManager"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x558, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folder
s"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
30
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
54
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"History", class:0x2, length:0x90, resultlength:0x78, handle:0x558, path:"\RE
GISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Wi
ndows\CurrentVersion\Explorer\User Shell Folders"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x530, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\
Volume"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x53C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\
Volume\{3095dd51-a141-42a6-8c53-8590cc53fbc1}\"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
30
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
64
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
58
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0x8000
0005, name:"Data", class:0x2, length:0x90, resultlength:0x566, handle:0x53C, pat
h:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Micros
oft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3095dd51-a141-42a68c53-8590cc53fbc1}"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Data", class:0x2, length:0x566, resultlength:0x566, handle:0x53C, path:"\REG
ISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Win
dows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3095dd51-a141-42a6-8c53-85
90cc53fbc1}"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
3C
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x53C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\
Volume"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x530, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\
Volume\{3095dd51-a141-42a6-8c53-8590cc53fbc1}\"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
3C
pid:4092, tid:1488, tick:0x33D701E, lvl:LOG, func:NtCreateFile, status:0xC000003
5, handle:0x0, access:0x100001, iostatus:0x331E528, information:0xA9206F, attrib
s:0x80, share:0x3, disposition:0x2, options:0x204021, path:"C:\Users\i92segoa"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Generation", class:0x2, length:0x90, resultlength:0x10, handle:0x530, path:"

\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft
\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3095dd51-a141-42a6-8c5
3-8590cc53fbc1}"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
30
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x530, c
lass:0x19, length:0x800, returnlength:0x14, sid:"S-1-16-8192", attributes:0x60
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
30
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:LdrResolveDelayLoadedAPI, stat
us:0x0, module:0x76B00000
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x530, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\
Volume"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x53C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\
Volume\{3095dd51-a141-42a6-8c53-8590cc53fbc1}\"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
30
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Generation", class:0x2, length:0x90, resultlength:0x10, handle:0x53C, path:"
\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft
\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3095dd51-a141-42a6-8c5
3-8590cc53fbc1}"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
3C
pid:4092, tid:1488, tick:0x33D701E, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x10, path:"C:\Users\i92segoa"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtDeviceIoControlFile, status:
0x0, iostatus:0x0, information:0x14, code:0x470807, inlen:0x24, outlen:0x14, han
dle:0xE4, path:"\Device\DeviceApi\CMApi"
pid:4092, tid:1488, tick:0x33D701E, lvl:LOG, func:NtCreateFile, status:0xC000003
5, handle:0x0, access:0x100001, iostatus:0x0, information:0xFFFFFFFF, attribs:0x
80, share:0x3, disposition:0x2, options:0x204021, path:"C:\Users\i92segoa\AppDat
a\Local"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtDeviceIoControlFile, status:
0x0, iostatus:0x0, information:0x652, code:0x470807, inlen:0x24, outlen:0x652, h
andle:0xE4, path:"\Device\DeviceApi\CMApi"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtDuplicateObject, status:0x0,
targethandle:0x53C, access:0x0, inherit:0x0, options:0x2, handle:0x51C
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtOpenFile, status:0x0, handle:0
x508, access:0x100080, iostatus:0x0, information:0x0, share:0x3, options:0x60, p
ath:"\??\STORAGE#Volume#{db216a5e-7a80-11e5-8d6c-806e6f6e6963}#0000000012D00000#
{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x53
0
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtQueryVolumeInformationFile, st
atus:0x0, iostatus:0x0, information:0x8, length:0x8, class:0x4, handle:0x508, pa
th:"\??\STORAGE#Volume#{db216a5e-7a80-11e5-8d6c-806e6f6e6963}#0000000012D00000#{
53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"
pid:4092, tid:1488, tick:0x33D701E, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x10, path:"C:\Users\i92segoa\AppData\Local"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x50
8
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtOpenFile, status:0x0, handle:0
x508, access:0x100080, iostatus:0x0, information:0x0, share:0x3, options:0x10, p
ath:"\??\STORAGE#Volume#{db216a5e-7a80-11e5-8d6c-806e6f6e6963}#0000000012D00000#

{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtDeviceIoControlFile, status:0x
0, iostatus:0x0, information:0x30, code:0x4D0008, inlen:0x0, outlen:0x208, handl
e:0x508, path:"\??\STORAGE#Volume#{db216a5e-7a80-11e5-8d6c-806e6f6e6963}#0000000
012D00000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x50
8
pid:4092, tid:1488, tick:0x33D701E, lvl:LOG, func:NtCreateFile, status:0xC000003
5, handle:0x0, access:0x100001, iostatus:0x0, information:0xFFFFFFFF, attribs:0x
80, share:0x3, disposition:0x2, options:0x204021, path:"C:\Users\i92segoa\AppDat
a\Local\Microsoft\Windows\History"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtCreateFile, status:0x0, handle
:0x508, access:0x100080, iostatus:0x0, information:0x0, attribs:0x80, share:0x3,
disposition:0x1, options:0x60, path:"\??\MountPointManager"
pid:4092, tid:556, tick:0x33D701E, lvl:LOG, func:NtDeviceIoControlFile, status:0
x80000005, iostatus:0x80000005, information:0x8, code:0x6D0008, inlen:0x46, outl
en:0x20, handle:0x508, path:"\??\MountPointManager"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtDeviceIoControlFile, status:0x
0, iostatus:0x0, information:0xC6, code:0x6D0008, inlen:0x46, outlen:0xC6, handl
e:0x508, path:"\??\MountPointManager"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x50
8
pid:4092, tid:1488, tick:0x33D701E, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x14, path:"C:\Users\i92segoa\AppData\Local\Microsoft\Windows\Histor
y"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:LdrUnloadDll, status:0x0, handle
:0x76B00000
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
51C
pid:4092, tid:1488, tick:0x33D701E, lvl:OK, func:NtSetInformationProcess, status
:0x0, class:0xC, length:0x4
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
53C
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handl
e:0x53C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246
3990887-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC
\Volume"
pid:4092, tid:1488, tick:0x33D701E, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x14, path:"C:\Users\i92segoa\AppData\Local\Microsoft\Windows\Histor
y"
pid:4092, tid:1488, tick:0x33D701E, lvl:OK, func:NtSetInformationProcess, status
:0x0, class:0xC, length:0x4
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handl
e:0x51C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246
3990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC
\Volume\{53fca6f1-4120-49f1-9dc9-20f142cb1ade}\"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
53C
pid:4092, tid:11200, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0x800
00005, name:"Data", class:0x2, length:0x90, resultlength:0x566, handle:0x51C, pa
th:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Micro
soft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{53fca6f1-4120-49f1
-9dc9-20f142cb1ade}"
pid:4092, tid:1488, tick:0x33D701E, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x2016, path:"C:\Users\i92segoa\AppData\Local\Microsoft\Windows\Hist
ory\History.IE5"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, n
ame:"Data", class:0x2, length:0x566, resultlength:0x566, handle:0x51C, path:"\RE
GISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Wi
ndows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{53fca6f1-4120-49f1-9dc9-2

0f142cb1ade}"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
51C
pid:4092, tid:1488, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x49C, access:0xF, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24639908
87-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Hi
story"
pid:4092, tid:1488, tick:0x33D701E, lvl:OK, func:NtSetValueKey, status:0x0, name
:"CachePrefix", index:0x0, type:0x1, size:0x12, handle:0x49C, path:"\REGISTRY\US
ER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Windows\Cur
rentVersion\Internet Settings\5.0\Cache\History"
pid:4092, tid:1488, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"CacheLimit", class:0x2, length:0x90, resultlength:0x10, handle:0x49C, path:"
\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft
\Windows\CurrentVersion\Internet Settings\5.0\Cache\History"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handl
e:0x51C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246
3990887-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC
\Volume"
pid:4092, tid:1488, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x4
9C
pid:4092, tid:1488, tick:0x33D701E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x49C, c
lass:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-2602383397-24
63990887-1001", attributes:0x0
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handl
e:0x53C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246
3990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC
\Volume\{53fca6f1-4120-49f1-9dc9-20f142cb1ade}\"
pid:4092, tid:1488, tick:0x33D701E, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x701C0000
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
51C
pid:4092, tid:1488, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x4
9C
pid:4092, tid:1488, tick:0x33D701E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x49C, c
lass:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-2602383397-24
63990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x92, handle:0x386, path:"\REGISTRY\USER\S-1-5-21
-2360094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, n
ame:"Generation", class:0x2, length:0x90, resultlength:0x10, handle:0x53C, path:
"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsof
t\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{53fca6f1-4120-49f1-9d
c9-20f142cb1ade}"
pid:4092, tid:1488, tick:0x33D701E, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x701C0000
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
53C
pid:4092, tid:1488, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x4
9C
pid:4092, tid:1488, tick:0x33D701E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtDuplicateObject, status:0x0,
targethandle:0x51C, access:0x0, inherit:0x0, options:0x2, handle:0x53C
pid:4092, tid:1488, tick:0x33D701E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF

FA, class:0x1D, length:0x4, returnlength:0x4


pid:4092, tid:1488, tick:0x33D701E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:1488, tick:0x33D701E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtOpenFile, status:0x0, handle:0
x508, access:0x100080, iostatus:0x0, information:0x0, share:0x3, options:0x60, p
ath:"\??\STORAGE#Volume#{db216a5e-7a80-11e5-8d6c-806e6f6e6963}#0000005D4AE00000#
{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x53
0
pid:4092, tid:1488, tick:0x33D701E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x49C, c
lass:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-2602383397-24
63990887-1001", attributes:0x0
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtQueryVolumeInformationFile, st
atus:0x0, iostatus:0x0, information:0x8, length:0x8, class:0x4, handle:0x508, pa
th:"\??\STORAGE#Volume#{db216a5e-7a80-11e5-8d6c-806e6f6e6963}#0000005D4AE00000#{
53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"
pid:4092, tid:1488, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x4
9C
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x50
8
pid:4092, tid:1488, tick:0x33D701E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x49C, c
lass:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-2602383397-24
63990887-1001", attributes:0x0
pid:4092, tid:1488, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x4
9C
pid:4092, tid:1488, tick:0x33D701E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtOpenFile, status:0x0, handle:0
x508, access:0x100080, iostatus:0x0, information:0x0, share:0x3, options:0x10, p
ath:"\??\STORAGE#Volume#{db216a5e-7a80-11e5-8d6c-806e6f6e6963}#0000005D4AE00000#
{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtDeviceIoControlFile, status:0x
0, iostatus:0x0, information:0x30, code:0x4D0008, inlen:0x0, outlen:0x208, handl
e:0x508, path:"\??\STORAGE#Volume#{db216a5e-7a80-11e5-8d6c-806e6f6e6963}#0000005
D4AE00000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x50
8
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtCreateFile, status:0x0, handle
:0x508, access:0x100080, iostatus:0x0, information:0x0, attribs:0x80, share:0x3,
disposition:0x1, options:0x60, path:"\??\MountPointManager"
pid:4092, tid:556, tick:0x33D701E, lvl:LOG, func:NtDeviceIoControlFile, status:0
x80000005, iostatus:0x80000005, information:0x8, code:0x6D0008, inlen:0x46, outl
en:0x20, handle:0x508, path:"\??\MountPointManager"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtDeviceIoControlFile, status:0x
0, iostatus:0x0, information:0xC6, code:0x6D0008, inlen:0x46, outlen:0xC6, handl
e:0x508, path:"\??\MountPointManager"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x50
8
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:LdrUnloadDll, status:0x0, handle
:0x76B00000
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
53C
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x

51C
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handl
e:0x51C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246
3990887-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC
\Volume"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handl
e:0x53C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246
3990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC
\Volume\{558339c2-fe4c-4d34-b973-1ff5b9ee3b95}\"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
51C
pid:4092, tid:11200, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0x800
00005, name:"Data", class:0x2, length:0x90, resultlength:0x566, handle:0x53C, pa
th:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Micro
soft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{558339c2-fe4c-4d34
-b973-1ff5b9ee3b95}"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, n
ame:"Data", class:0x2, length:0x566, resultlength:0x566, handle:0x53C, path:"\RE
GISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Wi
ndows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{558339c2-fe4c-4d34-b973-1
ff5b9ee3b95}"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
53C
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handl
e:0x53C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246
3990887-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC
\Volume"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handl
e:0x51C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246
3990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC
\Volume\{558339c2-fe4c-4d34-b973-1ff5b9ee3b95}\"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
53C
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, n
ame:"Generation", class:0x2, length:0x90, resultlength:0x10, handle:0x51C, path:
"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsof
t\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{558339c2-fe4c-4d34-b9
73-1ff5b9ee3b95}"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
51C
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtDuplicateObject, status:0x0,
targethandle:0x53C, access:0x0, inherit:0x0, options:0x2, handle:0x51C
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtOpenFile, status:0x0, handle:0
x508, access:0x100080, iostatus:0x0, information:0x0, share:0x3, options:0x60, p
ath:"\??\STORAGE#Volume#{db216a5e-7a80-11e5-8d6c-806e6f6e6963}#0000005D67000000#
{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x53
0
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtQueryVolumeInformationFile, st
atus:0x0, iostatus:0x0, information:0x8, length:0x8, class:0x4, handle:0x508, pa
th:"\??\STORAGE#Volume#{db216a5e-7a80-11e5-8d6c-806e6f6e6963}#0000005D67000000#{
53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x50
8
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtOpenFile, status:0x0, handle:0
x508, access:0x100080, iostatus:0x0, information:0x0, share:0x3, options:0x10, p
ath:"\??\STORAGE#Volume#{db216a5e-7a80-11e5-8d6c-806e6f6e6963}#0000005D67000000#
{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtDeviceIoControlFile, status:0x
0, iostatus:0x0, information:0x30, code:0x4D0008, inlen:0x0, outlen:0x208, handl

e:0x508, path:"\??\STORAGE#Volume#{db216a5e-7a80-11e5-8d6c-806e6f6e6963}#0000005
D67000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x50
8
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtCreateFile, status:0x0, handle
:0x508, access:0x100080, iostatus:0x0, information:0x0, attribs:0x80, share:0x3,
disposition:0x1, options:0x60, path:"\??\MountPointManager"
pid:4092, tid:556, tick:0x33D701E, lvl:LOG, func:NtDeviceIoControlFile, status:0
x80000005, iostatus:0x80000005, information:0x8, code:0x6D0008, inlen:0x46, outl
en:0x20, handle:0x508, path:"\??\MountPointManager"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtDeviceIoControlFile, status:0x
0, iostatus:0x0, information:0xFA, code:0x6D0008, inlen:0x46, outlen:0xFA, handl
e:0x508, path:"\??\MountPointManager"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x50
8
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:LdrUnloadDll, status:0x0, handle
:0x76B00000
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
51C
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
53C
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handl
e:0x53C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246
3990887-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC
\Volume"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handl
e:0x51C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246
3990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC
\Volume\{9391e3b4-adf4-4a69-b550-eac380a975b8}\"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
53C
pid:4092, tid:11200, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0x800
00005, name:"Data", class:0x2, length:0x90, resultlength:0x566, handle:0x51C, pa
th:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Micro
soft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{9391e3b4-adf4-4a69
-b550-eac380a975b8}"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, n
ame:"Data", class:0x2, length:0x566, resultlength:0x566, handle:0x51C, path:"\RE
GISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Wi
ndows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{9391e3b4-adf4-4a69-b550-e
ac380a975b8}"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
51C
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handl
e:0x51C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246
3990887-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC
\Volume"
pid:4092, tid:1488, tick:0x33D701E, lvl:WRN, func:New_NtQueryInformationToken::<
lambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0xC0000024, class:
0x1, length:0x40, returnlength:0xFFFFFFF8
pid:4092, tid:1488, tick:0x33D701E, lvl:WRN, func:New_NtQueryInformationToken::<
lambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0xC0000024, class:
0x1D, length:0x4, returnlength:0x0
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handl
e:0x53C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246
3990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC
\Volume\{9391e3b4-adf4-4a69-b550-eac380a975b8}\"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
51C
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0

x7, length:0x4, resultlength:0x4, handle:0x386, path:"\REGISTRY\USER\S-1-5-21-23


60094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:1488, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x564, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24639908
87-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, n
ame:"Generation", class:0x2, length:0x90, resultlength:0x10, handle:0x53C, path:
"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsof
t\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{9391e3b4-adf4-4a69-b5
50-eac380a975b8}"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
53C
pid:4092, tid:1488, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\K
nownFolders"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x538, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001_Classes\Directory"
pid:4092, tid:1488, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
64
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtDuplicateObject, status:0x0,
targethandle:0x51C, access:0x0, inherit:0x0, options:0x2, handle:0x53C
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0xA2, handle:0x53A, path:"\REGISTRY\USER\S-1-5-21
-2360094602-2602383397-2463990887-1001_CLASSES\Directory"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x53A, path:"\REGISTRY\USER\S-1-5-21-23
60094602-2602383397-2463990887-1001_CLASSES\Directory"
pid:4092, tid:1488, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x564, access:0x20019, path:"\REGISTRY\USER\.DEFAULT"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_CLASSES\Directory\ShellEx\IconHandler"
pid:4092, tid:1488, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x504, access:0x20019, path:"\REGISTRY\USER\.DEFAULT\Software\Microsoft\Windows
\CurrentVersion\Explorer\User Shell Folders"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtOpenFile, status:0x0, handle:0
x508, access:0x100080, iostatus:0x0, information:0x0, share:0x3, options:0x60, p
ath:"\??\STORAGE#Volume#{db216a5d-7a80-11e5-8d6c-806e6f6e6963}#0000000001100000#
{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\Registry\Machine\Software\Classes\Directory\She
llEx\IconHandler"
pid:4092, tid:1488, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
64
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x53
0
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x92, handle:0x386, path:"\REGISTRY\USER\S-1-5-21
-2360094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x386, path:"\REGISTRY\USER\S-1-5-21-23
60094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:1488, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Local AppData", class:0x2, length:0x90, resultlength:0x44, handle:0x504, pat
h:"\REGISTRY\USER\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Us
er Shell Folders"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtQueryVolumeInformationFile, st
atus:0x0, iostatus:0x0, information:0x8, length:0x8, class:0x4, handle:0x508, pa

th:"\??\STORAGE#Volume#{db216a5d-7a80-11e5-8d6c-806e6f6e6963}#0000000001100000#{
53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001_Classes\Folder"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x50
8
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x558, access:0x20019, path:"\Registry\Machine\Software\Classes\Folder"
pid:4092, tid:1488, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x564, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows NT\Cu
rrentVersion\ProfileList"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x56, handle:0x55A, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\Folder"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x55A, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\Folder"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtOpenFile, status:0x0, handle:0
x508, access:0x100080, iostatus:0x0, information:0x0, share:0x3, options:0x10, p
ath:"\??\STORAGE#Volume#{db216a5d-7a80-11e5-8d6c-806e6f6e6963}#0000000001100000#
{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"
pid:4092, tid:1488, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Default", class:0x2, length:0x90, resultlength:0x44, handle:0x564, path:"\RE
GISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\ProfileList"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtDeviceIoControlFile, status:0x
0, iostatus:0x0, information:0x30, code:0x4D0008, inlen:0x0, outlen:0x208, handl
e:0x508, path:"\??\STORAGE#Volume#{db216a5d-7a80-11e5-8d6c-806e6f6e6963}#0000000
001100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"
pid:4092, tid:1488, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Default", class:0x2, length:0x90, resultlength:0x44, handle:0x564, path:"\RE
GISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\ProfileList"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_Classes\Folder\ShellEx\IconHandler"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x50
8
pid:4092, tid:1488, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
64
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\Folder\ShellE
x\IconHandler"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x92, handle:0x386, path:"\REGISTRY\USER\S-1-5-21
-2360094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x386, path:"\REGISTRY\USER\S-1-5-21-23
60094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtCreateFile, status:0x0, handle
:0x508, access:0x100080, iostatus:0x0, information:0x0, attribs:0x80, share:0x3,
disposition:0x1, options:0x60, path:"\??\MountPointManager"
pid:4092, tid:1488, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
04
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001_Classes\AllFilesystemObjects"

pid:4092, tid:556, tick:0x33D701E, lvl:LOG, func:NtDeviceIoControlFile, status:0


x80000005, iostatus:0x80000005, information:0x8, code:0x6D0008, inlen:0x46, outl
en:0x20, handle:0x508, path:"\??\MountPointManager"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x55C, access:0x20019, path:"\Registry\Machine\Software\Classes\AllFilesystemOb
jects"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x72, handle:0x55E, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\AllFilesystemObjects"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtDeviceIoControlFile, status:0x
0, iostatus:0x0, information:0xFA, code:0x6D0008, inlen:0x46, outlen:0xFA, handl
e:0x508, path:"\??\MountPointManager"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x55E, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\AllFilesystemObjects"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x50
8
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:LdrUnloadDll, status:0x0, handle
:0x76B00000
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
53C
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_Classes\AllFilesystemObjects\ShellEx\IconHandler"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
51C
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\AllFilesystem
Objects\ShellEx\IconHandler"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0xA2, handle:0x53A, path:"\REGISTRY\USER\S-1-5-21
-2360094602-2602383397-2463990887-1001_CLASSES\Directory"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x53A, path:"\REGISTRY\USER\S-1-5-21-23
60094602-2602383397-2463990887-1001_CLASSES\Directory"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handl
e:0x51C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246
3990887-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC
\Volume"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x554, access:0x2000000, path:"\Registry\Machine\Software\Classes\Directory"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DocObject", class:0x2, length:0x90, resultlength:0x0, handle:0x53A,
path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001_CLASSES\Dire
ctory"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handl
e:0x53C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246
3990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC
\Volume\{3095dd51-a141-42a6-8c53-8590cc53fbc1}\"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DocObject", class:0x2, length:0x90, resultlength:0x0, handle:0x556,
path:"\REGISTRY\MACHINE\SOFTWARE\Classes\Directory"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
51C
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
56

pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0


x3, length:0x180, resultlength:0xA2, handle:0x53A, path:"\REGISTRY\USER\S-1-5-21
-2360094602-2602383397-2463990887-1001_CLASSES\Directory"
pid:4092, tid:11200, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0x800
00005, name:"Data", class:0x2, length:0x90, resultlength:0x566, handle:0x53C, pa
th:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Micro
soft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3095dd51-a141-42a6
-8c53-8590cc53fbc1}"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x53A, path:"\REGISTRY\USER\S-1-5-21-23
60094602-2602383397-2463990887-1001_CLASSES\Directory"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_CLASSES\Directory\DocObject"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, n
ame:"Data", class:0x2, length:0x566, resultlength:0x566, handle:0x53C, path:"\RE
GISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Wi
ndows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3095dd51-a141-42a6-8c53-8
590cc53fbc1}"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\Registry\Machine\Software\Classes\Directory\Doc
Object"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
53C
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0x56, handle:0x55A, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\Folder"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x55A, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\Folder"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handl
e:0x53C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246
3990887-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC
\Volume"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\Folder"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DocObject", class:0x2, length:0x90, resultlength:0x0, handle:0x55A,
path:"\REGISTRY\MACHINE\SOFTWARE\Classes\Folder"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handl
e:0x51C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246
3990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC
\Volume\{3095dd51-a141-42a6-8c53-8590cc53fbc1}\"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x56, handle:0x55A, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\Folder"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
53C
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x55A, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\Folder"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0

pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, n


ame:"Generation", class:0x2, length:0x90, resultlength:0x10, handle:0x51C, path:
"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsof
t\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3095dd51-a141-42a6-8c
53-8590cc53fbc1}"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_Classes\Folder\DocObject"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
51C
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\Folder\DocObj
ect"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0x72, handle:0x55E, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\AllFilesystemObjects"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtDuplicateObject, status:0x0,
targethandle:0x53C, access:0x0, inherit:0x0, options:0x2, handle:0x51C
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x55E, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\AllFilesystemObjects"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\AllFilesystemObjects"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtOpenFile, status:0x0, handle:0
x508, access:0x100080, iostatus:0x0, information:0x0, share:0x3, options:0x60, p
ath:"\??\STORAGE#Volume#{db216a5d-7a80-11e5-8d6c-806e6f6e6963}#0000003A1BD00000#
{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x53
0
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DocObject", class:0x2, length:0x90, resultlength:0x0, handle:0x55E,
path:"\REGISTRY\MACHINE\SOFTWARE\Classes\AllFilesystemObjects"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtQueryVolumeInformationFile, st
atus:0x0, iostatus:0x0, information:0x8, length:0x8, class:0x4, handle:0x508, pa
th:"\??\STORAGE#Volume#{db216a5d-7a80-11e5-8d6c-806e6f6e6963}#0000003A1BD00000#{
53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x50
8
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x72, handle:0x55E, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\AllFilesystemObjects"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x55E, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\AllFilesystemObjects"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtOpenFile, status:0x0, handle:0
x508, access:0x100080, iostatus:0x0, information:0x0, share:0x3, options:0x10, p
ath:"\??\STORAGE#Volume#{db216a5d-7a80-11e5-8d6c-806e6f6e6963}#0000003A1BD00000#
{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtDeviceIoControlFile, status:0x
0, iostatus:0x0, information:0x30, code:0x4D0008, inlen:0x0, outlen:0x208, handl
e:0x508, path:"\??\STORAGE#Volume#{db216a5d-7a80-11e5-8d6c-806e6f6e6963}#0000003

A1BD00000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x50
8
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_Classes\AllFilesystemObjects\DocObject"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtCreateFile, status:0x0, handle
:0x508, access:0x100080, iostatus:0x0, information:0x0, attribs:0x80, share:0x3,
disposition:0x1, options:0x60, path:"\??\MountPointManager"
pid:4092, tid:556, tick:0x33D701E, lvl:LOG, func:NtDeviceIoControlFile, status:0
x80000005, iostatus:0x80000005, information:0x8, code:0x6D0008, inlen:0x46, outl
en:0x20, handle:0x508, path:"\??\MountPointManager"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\AllFilesystem
Objects\DocObject"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtDeviceIoControlFile, status:0x
0, iostatus:0x0, information:0xC6, code:0x6D0008, inlen:0x46, outlen:0xC6, handl
e:0x508, path:"\??\MountPointManager"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x50
8
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0xA2, handle:0x53A, path:"\REGISTRY\USER\S-1-5-21
-2360094602-2602383397-2463990887-1001_CLASSES\Directory"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:LdrUnloadDll, status:0x0, handle
:0x76B00000
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
51C
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x53A, path:"\REGISTRY\USER\S-1-5-21-23
60094602-2602383397-2463990887-1001_CLASSES\Directory"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
53C
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x504, access:0x2000000, path:"\Registry\Machine\Software\Classes\Directory"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"BrowseInPlace", class:0x2, length:0x90, resultlength:0x0, handle:0x5
3A, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001_CLASSES\
Directory"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"BrowseInPlace", class:0x2, length:0x90, resultlength:0x0, handle:0x5
06, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\Directory"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handl
e:0x53C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246
3990887-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC
\Volume"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
06
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0xA2, handle:0x53A, path:"\REGISTRY\USER\S-1-5-21
-2360094602-2602383397-2463990887-1001_CLASSES\Directory"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x53A, path:"\REGISTRY\USER\S-1-5-21-23
60094602-2602383397-2463990887-1001_CLASSES\Directory"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handl
e:0x51C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246
3990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC
\Volume\{cf83ff88-1dd4-4efd-a654-a8dcebea22af}\"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_CLASSES\Directory\BrowseInPlace"

pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x


53C
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\Registry\Machine\Software\Classes\Directory\Bro
wseInPlace"
pid:4092, tid:11200, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0x800
00005, name:"Data", class:0x2, length:0x90, resultlength:0x566, handle:0x51C, pa
th:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Micro
soft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{cf83ff88-1dd4-4efd
-a654-a8dcebea22af}"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0x56, handle:0x55A, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\Folder"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x55A, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\Folder"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, n
ame:"Data", class:0x2, length:0x566, resultlength:0x566, handle:0x51C, path:"\RE
GISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Wi
ndows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{cf83ff88-1dd4-4efd-a654-a
8dcebea22af}"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
51C
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\Folder"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"BrowseInPlace", class:0x2, length:0x90, resultlength:0x0, handle:0x5
5A, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\Folder"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x56, handle:0x55A, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\Folder"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handl
e:0x51C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246
3990887-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC
\Volume"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x55A, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\Folder"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handl
e:0x53C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246
3990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC
\Volume\{cf83ff88-1dd4-4efd-a654-a8dcebea22af}\"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_Classes\Folder\BrowseInPlace"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
51C
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\Folder\Browse
InPlace"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0

x3, length:0x188, resultlength:0x72, handle:0x55E, path:"\REGISTRY\MACHINE\SOFTW


ARE\Classes\AllFilesystemObjects"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, n
ame:"Generation", class:0x2, length:0x90, resultlength:0x10, handle:0x53C, path:
"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsof
t\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{cf83ff88-1dd4-4efd-a6
54-a8dcebea22af}"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x55E, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\AllFilesystemObjects"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
53C
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\AllFilesystemObjects"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtDuplicateObject, status:0x0,
targethandle:0x51C, access:0x0, inherit:0x0, options:0x2, handle:0x53C
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"BrowseInPlace", class:0x2, length:0x90, resultlength:0x0, handle:0x5
5E, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\AllFilesystemObjects"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x72, handle:0x55E, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\AllFilesystemObjects"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x55E, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\AllFilesystemObjects"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtOpenFile, status:0x0, handle:0
x508, access:0x100080, iostatus:0x0, information:0x0, share:0x3, options:0x60, p
ath:"\??\STORAGE#Volume#{db216a5e-7a80-11e5-8d6c-806e6f6e6963}#000000E3E0D00000#
{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x53
0
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtQueryVolumeInformationFile, st
atus:0x0, iostatus:0x0, information:0x8, length:0x8, class:0x4, handle:0x508, pa
th:"\??\STORAGE#Volume#{db216a5e-7a80-11e5-8d6c-806e6f6e6963}#000000E3E0D00000#{
53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x50
8
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_Classes\AllFilesystemObjects\BrowseInPlace"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtOpenFile, status:0x0, handle:0
x508, access:0x100080, iostatus:0x0, information:0x0, share:0x3, options:0x10, p
ath:"\??\STORAGE#Volume#{db216a5e-7a80-11e5-8d6c-806e6f6e6963}#000000E3E0D00000#
{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtDeviceIoControlFile, status:0x
0, iostatus:0x0, information:0x32, code:0x4D0008, inlen:0x0, outlen:0x208, handl
e:0x508, path:"\??\STORAGE#Volume#{db216a5e-7a80-11e5-8d6c-806e6f6e6963}#000000E
3E0D00000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\AllFilesystem
Objects\BrowseInPlace"

pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x50


8
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0xA2, handle:0x53A, path:"\REGISTRY\USER\S-1-5-21
-2360094602-2602383397-2463990887-1001_CLASSES\Directory"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtCreateFile, status:0x0, handle
:0x508, access:0x100080, iostatus:0x0, information:0x0, attribs:0x80, share:0x3,
disposition:0x1, options:0x60, path:"\??\MountPointManager"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x53A, path:"\REGISTRY\USER\S-1-5-21-23
60094602-2602383397-2463990887-1001_CLASSES\Directory"
pid:4092, tid:556, tick:0x33D701E, lvl:LOG, func:NtDeviceIoControlFile, status:0
x80000005, iostatus:0x80000005, information:0x8, code:0x6D0008, inlen:0x48, outl
en:0x20, handle:0x508, path:"\??\MountPointManager"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_CLASSES\Directory\Clsid"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtDeviceIoControlFile, status:0x
0, iostatus:0x0, information:0xC8, code:0x6D0008, inlen:0x48, outlen:0xC8, handl
e:0x508, path:"\??\MountPointManager"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\Registry\Machine\Software\Classes\Directory\Cls
id"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x50
8
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x56, handle:0x55A, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\Folder"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:LdrUnloadDll, status:0x0, handle
:0x76B00000
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x55A, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\Folder"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
53C
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
51C
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_Classes\Folder\Clsid"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handl
e:0x51C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246
3990887-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC
\Volume"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\Folder\Clsid"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x72, handle:0x55E, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\AllFilesystemObjects"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handl
e:0x560, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246
3990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC
\Volume\{24912961-6cfd-4b5f-aacb-0a741b920810}\"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x55E, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\AllFilesystemObjects"

pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x


51C
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:11200, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0x800
00005, name:"Data", class:0x2, length:0x90, resultlength:0x566, handle:0x560, pa
th:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Micro
soft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{24912961-6cfd-4b5f
-aacb-0a741b920810}"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_Classes\AllFilesystemObjects\Clsid"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, n
ame:"Data", class:0x2, length:0x566, resultlength:0x566, handle:0x560, path:"\RE
GISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Wi
ndows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{24912961-6cfd-4b5f-aacb-0
a741b920810}"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
560
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\AllFilesystem
Objects\Clsid"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0xA2, handle:0x53A, path:"\REGISTRY\USER\S-1-5-21
-2360094602-2602383397-2463990887-1001_CLASSES\Directory"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handl
e:0x560, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246
3990887-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC
\Volume"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x53A, path:"\REGISTRY\USER\S-1-5-21-23
60094602-2602383397-2463990887-1001_CLASSES\Directory"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handl
e:0x51C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246
3990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC
\Volume\{24912961-6cfd-4b5f-aacb-0a741b920810}\"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x554, access:0x2000000, path:"\Registry\Machine\Software\Classes\Directory"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
560
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"IsShortcut", class:0x2, length:0x90, resultlength:0x0, handle:0x53A,
path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001_CLASSES\Dir
ectory"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, n
ame:"Generation", class:0x2, length:0x90, resultlength:0x10, handle:0x51C, path:
"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsof
t\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{24912961-6cfd-4b5f-aa
cb-0a741b920810}"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
51C
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"IsShortcut", class:0x2, length:0x90, resultlength:0x0, handle:0x556,
path:"\REGISTRY\MACHINE\SOFTWARE\Classes\Directory"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
56
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtDuplicateObject, status:0x0,
targethandle:0x560, access:0x0, inherit:0x0, options:0x2, handle:0x51C

pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0


x3, length:0x188, resultlength:0x56, handle:0x55A, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\Folder"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x55A, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\Folder"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtOpenFile, status:0x0, handle:0
x504, access:0x100080, iostatus:0x0, information:0x0, share:0x3, options:0x60, p
ath:"\??\STORAGE#Volume#{db216a5e-7a80-11e5-8d6c-806e6f6e6963}#0000000040500000#
{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\Folder"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x56
4
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"IsShortcut", class:0x2, length:0x90, resultlength:0x0, handle:0x55A,
path:"\REGISTRY\MACHINE\SOFTWARE\Classes\Folder"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtQueryVolumeInformationFile, st
atus:0x0, iostatus:0x0, information:0x8, length:0x8, class:0x4, handle:0x504, pa
th:"\??\STORAGE#Volume#{db216a5e-7a80-11e5-8d6c-806e6f6e6963}#0000000040500000#{
53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0x72, handle:0x55E, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\AllFilesystemObjects"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x50
4
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x55E, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\AllFilesystemObjects"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtOpenFile, status:0x0, handle:0
x504, access:0x100080, iostatus:0x0, information:0x0, share:0x3, options:0x10, p
ath:"\??\STORAGE#Volume#{db216a5e-7a80-11e5-8d6c-806e6f6e6963}#0000000040500000#
{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\AllFilesystemObjects"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtDeviceIoControlFile, status:0x
0, iostatus:0x0, information:0x30, code:0x4D0008, inlen:0x0, outlen:0x208, handl
e:0x504, path:"\??\STORAGE#Volume#{db216a5e-7a80-11e5-8d6c-806e6f6e6963}#0000000
040500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"IsShortcut", class:0x2, length:0x90, resultlength:0x0, handle:0x55E,
path:"\REGISTRY\MACHINE\SOFTWARE\Classes\AllFilesystemObjects"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x50
4
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0xA2, handle:0x53A, path:"\REGISTRY\USER\S-1-5-21
-2360094602-2602383397-2463990887-1001_CLASSES\Directory"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x53A, path:"\REGISTRY\USER\S-1-5-21-23
60094602-2602383397-2463990887-1001_CLASSES\Directory"

pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtCreateFile, status:0x0, handle


:0x504, access:0x100080, iostatus:0x0, information:0x0, attribs:0x80, share:0x3,
disposition:0x1, options:0x60, path:"\??\MountPointManager"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x554, access:0x2000000, path:"\Registry\Machine\Software\Classes\Directory"
pid:4092, tid:556, tick:0x33D701E, lvl:LOG, func:NtDeviceIoControlFile, status:0
x80000005, iostatus:0x80000005, information:0x8, code:0x6D0008, inlen:0x46, outl
en:0x20, handle:0x504, path:"\??\MountPointManager"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"AlwaysShowExt", class:0x2, length:0x90, resultlength:0x0, handle:0x5
3A, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001_CLASSES\
Directory"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtDeviceIoControlFile, status:0x
0, iostatus:0x0, information:0xFA, code:0x6D0008, inlen:0x46, outlen:0xFA, handl
e:0x504, path:"\??\MountPointManager"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x50
4
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"AlwaysShowExt", class:0x2, length:0x90, resultlength:0xE, handle:0x556, path
:"\REGISTRY\MACHINE\SOFTWARE\Classes\Directory"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:LdrUnloadDll, status:0x0, handle
:0x76B00000
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
56
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
51C
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
560
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0xA2, handle:0x53A, path:"\REGISTRY\USER\S-1-5-21
-2360094602-2602383397-2463990887-1001_CLASSES\Directory"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x53A, path:"\REGISTRY\USER\S-1-5-21-23
60094602-2602383397-2463990887-1001_CLASSES\Directory"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handl
e:0x560, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246
3990887-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC
\Volume"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x554, access:0x2000000, path:"\Registry\Machine\Software\Classes\Directory"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handl
e:0x564, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246
3990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC
\Volume\{7200359d-96f0-4a96-9857-6e59f29ae985}\"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
560
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"NeverShowExt", class:0x2, length:0x90, resultlength:0xE, handle:0x53
A, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001_CLASSES\D
irectory"
pid:4092, tid:11200, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0x800
00005, name:"Data", class:0x2, length:0x90, resultlength:0x566, handle:0x564, pa
th:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Micro
soft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{7200359d-96f0-4a96
-9857-6e59f29ae985}"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"NeverShowExt", class:0x2, length:0x90, resultlength:0xE, handle:0x55
6, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\Directory"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, n
ame:"Data", class:0x2, length:0x566, resultlength:0x566, handle:0x564, path:"\RE

GISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Wi
ndows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{7200359d-96f0-4a96-9857-6
e59f29ae985}"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
56
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
564
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0x56, handle:0x55A, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\Folder"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handl
e:0x564, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246
3990887-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC
\Volume"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x55A, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\Folder"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handl
e:0x560, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246
3990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC
\Volume\{7200359d-96f0-4a96-9857-6e59f29ae985}\"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
564
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, n
ame:"Generation", class:0x2, length:0x90, resultlength:0x10, handle:0x560, path:
"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsof
t\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{7200359d-96f0-4a96-98
57-6e59f29ae985}"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
560
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\Folder"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"NeverShowExt", class:0x2, length:0x90, resultlength:0xE, handle:0x55
A, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\Folder"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtCreateFile, status:0x0, hand
le:0x560, access:0x100080, iostatus:0x0, information:0x0, attribs:0x80, share:0x
3, disposition:0x1, options:0x60, path:"\??\MountPointManager"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0x72, handle:0x55E, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\AllFilesystemObjects"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtDeviceIoControlFile, status:
0x0, iostatus:0x0, information:0x6, code:0x6D0034, inlen:0x208, outlen:0x8, hand
le:0x560, path:"\??\MountPointManager"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x55E, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\AllFilesystemObjects"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
560
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtCreateFile, status:0x0, hand
le:0x560, access:0x100080, iostatus:0x0, information:0x0, attribs:0x80, share:0x

3, disposition:0x1, options:0x60, path:"\??\MountPointManager"


pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtDeviceIoControlFile, status:
0x0, iostatus:0x0, information:0x6, code:0x6D0034, inlen:0x208, outlen:0x8, hand
le:0x560, path:"\??\MountPointManager"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\AllFilesystemObjects"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
560
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"NeverShowExt", class:0x2, length:0x90, resultlength:0xE, handle:0x55
E, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\AllFilesystemObjects"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtCreateFile, status:0x0, hand
le:0x560, access:0x100080, iostatus:0x0, information:0x0, attribs:0x80, share:0x
3, disposition:0x1, options:0x60, path:"\??\MountPointManager"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
3A
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtDeviceIoControlFile, status:
0x0, iostatus:0x0, information:0x6, code:0x6D0034, inlen:0x208, outlen:0x8, hand
le:0x560, path:"\??\MountPointManager"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
5A
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
560
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
5E
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtCreateFile, status:0x0, hand
le:0x560, access:0x100080, iostatus:0x0, information:0x0, attribs:0x80, share:0x
3, disposition:0x1, options:0x60, path:"\??\MountPointManager"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtDeviceIoControlFile, status:
0x0, iostatus:0x0, information:0x6, code:0x6D0034, inlen:0x208, outlen:0x8, hand
le:0x560, path:"\??\MountPointManager"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
560
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x92, handle:0x386, path:"\REGISTRY\USER\S-1-5-21
-2360094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtCreateFile, status:0x0, hand
le:0x560, access:0x100080, iostatus:0x0, information:0x0, attribs:0x80, share:0x
3, disposition:0x1, options:0x60, path:"\??\MountPointManager"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x386, path:"\REGISTRY\USER\S-1-5-21-23
60094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:11200, tick:0x33D701E, lvl:LOG, func:NtDeviceIoControlFile, status
:0x80000005, iostatus:0x80000005, information:0x4, code:0x6D0034, inlen:0x208, o
utlen:0x8, handle:0x560, path:"\??\MountPointManager"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtDeviceIoControlFile, status:
0x0, iostatus:0x0, information:0xC, code:0x6D0034, inlen:0x208, outlen:0x10, han
dle:0x560, path:"\??\MountPointManager"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001_Classes\CLSID\{F324E4F9-8496-40B2-A1FF-9617C1C9AFFE}\Instance"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
560
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtCreateFile, status:0x0, hand
le:0x560, access:0x100080, iostatus:0x0, information:0x0, attribs:0x80, share:0x
3, disposition:0x1, options:0x60, path:"\??\MountPointManager"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\Registry\Machine\Software\Classes\CLSID\{F3
24E4F9-8496-40B2-A1FF-9617C1C9AFFE}\Instance"

pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:LdrLoadDll, status:0x0, flags:0


x0, module:"shell32.dll", handle:0x75670000
pid:4092, tid:11200, tick:0x33D701E, lvl:LOG, func:NtDeviceIoControlFile, status
:0x80000005, iostatus:0x80000005, information:0x4, code:0x6D0034, inlen:0x208, o
utlen:0x8, handle:0x560, path:"\??\MountPointManager"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x75670000, name:"DllGetClassObject", ordinal:0x0, address:
0x757FDCA0, image:0x0, caller:0x76CCD1BF
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtDeviceIoControlFile, status:
0x0, iostatus:0x0, information:0xC, code:0x6D0034, inlen:0x208, outlen:0x10, han
dle:0x560, path:"\??\MountPointManager"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
560
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:New_NtQueryInformationToken::<
lambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x560,
class:0x19, length:0x800, returnlength:0x14, sid:"S-1-16-8192", attributes:0x60
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenMutant, status:0xC000003
4, handle:0x0, access:0x100001, path:"\Sessions\1\BaseNamedObjects\Global\SyncRo
otManager"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
560
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x75670000
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtCreateFile, status:0x0, hand
le:0x560, access:0x100080, iostatus:0x0, information:0x0, attribs:0x80, share:0x
3, disposition:0x1, options:0x60, path:"\??\MountPointManager"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:11200, tick:0x33D701E, lvl:LOG, func:NtDeviceIoControlFile, status
:0x80000005, iostatus:0x80000005, information:0x4, code:0x6D0034, inlen:0x208, o
utlen:0x8, handle:0x560, path:"\??\MountPointManager"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtDeviceIoControlFile, status:
0x0, iostatus:0x0, information:0xC, code:0x6D0034, inlen:0x208, outlen:0x10, han
dle:0x560, path:"\??\MountPointManager"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
560
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtCreateFile, status:0x0, hand
le:0x560, access:0x100080, iostatus:0x0, information:0x0, attribs:0x80, share:0x
3, disposition:0x1, options:0x60, path:"\??\MountPointManager"
pid:4092, tid:11200, tick:0x33D701E, lvl:LOG, func:NtDeviceIoControlFile, status
:0x80000005, iostatus:0x80000005, information:0x4, code:0x6D0034, inlen:0x208, o
utlen:0x8, handle:0x560, path:"\??\MountPointManager"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtDeviceIoControlFile, status:
0x0, iostatus:0x0, information:0xC, code:0x6D0034, inlen:0x208, outlen:0x10, han
dle:0x560, path:"\??\MountPointManager"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
560
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:New_NtQueryInformationToken::<
lambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x560,
class:0x19, length:0x800, returnlength:0x14, sid:"S-1-16-8192", attributes:0x60
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
560
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtCreateFile, status:0x0, hand
le:0x560, access:0x100080, iostatus:0x0, information:0x0, attribs:0x80, share:0x
3, disposition:0x1, options:0x60, path:"\??\MountPointManager"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtDeviceIoControlFile, status:
0x0, iostatus:0x0, information:0x6, code:0x6D0034, inlen:0x208, outlen:0x8, hand
le:0x560, path:"\??\MountPointManager"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtCreateMutant, status:0x0, han

dle:0x558, access:0x100001, owner:0x0, path:"\Sessions\1\BaseNamedObjects\Global


\SyncRootManager"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
560
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtCreateFile, status:0x0, hand
le:0x560, access:0x100080, iostatus:0x0, information:0x0, attribs:0x80, share:0x
3, disposition:0x1, options:0x60, path:"\??\MountPointManager"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtDeviceIoControlFile, status:
0x0, iostatus:0x0, information:0x6, code:0x6D0034, inlen:0x208, outlen:0x8, hand
le:0x560, path:"\??\MountPointManager"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x538, access:0x20119, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\Curre
ntVersion\Explorer\SyncRootManager"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
560
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtCreateFile, status:0x0, hand
le:0x560, access:0x100080, iostatus:0x0, information:0x0, attribs:0x80, share:0x
3, disposition:0x1, options:0x60, path:"\??\MountPointManager"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtCreateKey, status:0x0, handle
:0x554, access:0x10, title:0x0, class:"", options:0x0, disposition:0x2, path:"\R
EGISTRY\MACHINE\SOFTWARE\MICROSOFT\Windows\CurrentVersion\Explorer\SyncRootManag
er\"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtDeviceIoControlFile, status:
0x0, iostatus:0x0, information:0x6, code:0x6D0034, inlen:0x208, outlen:0x8, hand
le:0x560, path:"\??\MountPointManager"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
560
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtNotifyChangeKey, status:0x103
, event:0x56C, iostatus:0x103, information:0x0, filter:0x10000005, watch:0x1, le
ngth:0x0, async:0x1, handle:0x554, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Wi
ndows\CurrentVersion\Explorer\SyncRootManager"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x570, iocompletion:0x38, handle:0x56C
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtCreateFile, status:0x0, hand
le:0x560, access:0x100080, iostatus:0x0, information:0x0, attribs:0x80, share:0x
3, disposition:0x1, options:0x60, path:"\??\MountPointManager"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x75670000
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtDeviceIoControlFile, status:
0x0, iostatus:0x0, information:0x6, code:0x6D0034, inlen:0x208, outlen:0x8, hand
le:0x560, path:"\??\MountPointManager"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x4, length:0xB0, resultlength:0x28, handle:0x538, path:"\REGISTRY\MACHINE\SOFTWA
RE\MICROSOFT\Windows\CurrentVersion\Explorer\SyncRootManager"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
560
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x0, class:0x0, length:0x120, resultlength:0x8E, handle:0x538, path:"\REGISTR
Y\MACHINE\SOFTWARE\MICROSOFT\Windows\CurrentVersion\Explorer\SyncRootManager"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtCreateFile, status:0x0, hand
le:0x560, access:0x100080, iostatus:0x0, information:0x0, attribs:0x80, share:0x
3, disposition:0x1, options:0x60, path:"\??\MountPointManager"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x574, access:0x20119, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Windows\Curre
ntVersion\Explorer\SyncRootManager\Dropbox!S-1-5-21-2360094602-2602383397-246399
0887-1001!personal"
pid:4092, tid:11200, tick:0x33D701E, lvl:LOG, func:NtDeviceIoControlFile, status
:0x80000005, iostatus:0x80000005, information:0x4, code:0x6D0034, inlen:0x208, o
utlen:0x8, handle:0x560, path:"\??\MountPointManager"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na

me:"DisplayNameResource", class:0x2, length:0x90, resultlength:0x1C, handle:0x57


4, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Windows\CurrentVersion\Explorer\Sy
ncRootManager\Dropbox!S-1-5-21-2360094602-2602383397-2463990887-1001!personal"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtDeviceIoControlFile, status:
0x0, iostatus:0x0, information:0xC, code:0x6D0034, inlen:0x208, outlen:0x10, han
dle:0x560, path:"\??\MountPointManager"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
560
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtDuplicateObject, status:0x0,
targethandle:0x4D4, access:0x0, inherit:0x0, options:0x2, handle:0xFFFFFFFE
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"IconResource", class:0x2, length:0x90, resultlength:0x7C, handle:0x574, path
:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Windows\CurrentVersion\Explorer\SyncRootM
anager\Dropbox!S-1-5-21-2360094602-2602383397-2463990887-1001!personal"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtCreateFile, status:0x0, hand
le:0x560, access:0x100080, iostatus:0x0, information:0x0, attribs:0x80, share:0x
3, disposition:0x1, options:0x60, path:"\??\MountPointManager"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"C:\WINDOWS\system32\mswsock.dll", handle:0x73700000
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Flags", class:0x2, length:0x90, resultlength:0x10, handle:0x574, path:"\REGI
STRY\MACHINE\SOFTWARE\MICROSOFT\Windows\CurrentVersion\Explorer\SyncRootManager\
Dropbox!S-1-5-21-2360094602-2602383397-2463990887-1001!personal"
pid:4092, tid:11200, tick:0x33D701E, lvl:LOG, func:NtDeviceIoControlFile, status
:0x80000005, iostatus:0x80000005, information:0x4, code:0x6D0034, inlen:0x208, o
utlen:0x8, handle:0x560, path:"\??\MountPointManager"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x73700000, name:"WSPStartup", ordinal:0x0, address:0x7370D
350, image:0x0, caller:0x775F7454
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtDeviceIoControlFile, status:
0x0, iostatus:0x0, information:0xC, code:0x6D0034, inlen:0x208, outlen:0x10, han
dle:0x560, path:"\??\MountPointManager"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Handler", class:0x2, length:0x90, resultlength:0x19E8B0, handle:0x57
4, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Windows\CurrentVersion\Explorer\Sy
ncRootManager\Dropbox!S-1-5-21-2360094602-2602383397-2463990887-1001!personal"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
560
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:New_NtQueryInformationToken::<
lambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x560,
class:0x19, length:0x800, returnlength:0x14, sid:"S-1-16-8192", attributes:0x60
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
560
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x578, access:0x20119, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Windows\Curre
ntVersion\Explorer\SyncRootManager\Dropbox!S-1-5-21-2360094602-2602383397-246399
0887-1001!personal\UserSyncRoots"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:LdrUnloadDll, status:0x0, hand
le:0x76B00000
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x50C, access:0x20019, path:"\REGISTRY\MACHINE\SYSTEM\CurrentControlSet\Service
s\Winsock\Parameters"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:LdrUnloadDll, status:0x0, hand
le:0x74B20000
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x4, length:0xB0, resultlength:0x28, handle:0x578, path:"\REGISTRY\MACHINE\SOFTWA
RE\MICROSOFT\Windows\CurrentVersion\Explorer\SyncRootManager\Dropbox!S-1-5-21-23
60094602-2602383397-2463990887-1001!personal\UserSyncRoots"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Transports", class:0x2, length:0x90, resultlength:0x42, handle:0x50C, path:"

\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Winsock\Parameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtEnumerateValueKey, status:0x0
, index:0x0, class:0x1, length:0x186, resultlength:0x86, handle:0x578, path:"\RE
GISTRY\MACHINE\SOFTWARE\MICROSOFT\Windows\CurrentVersion\Explorer\SyncRootManage
r\Dropbox!S-1-5-21-2360094602-2602383397-2463990887-1001!personal\UserSyncRoots"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Transports", class:0x2, length:0x90, resultlength:0x42, handle:0x50C, path:"
\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Winsock\Parameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
78
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
0C
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20119, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Windows
\CurrentVersion\Explorer\SyncRootManager\Dropbox!S-1-5-21-2360094602-26023833972463990887-1001!personal\PendingRedirectionSyncRoots"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
74
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
38
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x50C, access:0x20019, path:"\REGISTRY\MACHINE\System\CurrentControlSet\Service
s\Psched\Parameters\Winsock"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
58
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0x8000
0005, name:"Mapping", class:0x2, length:0x90, resultlength:0xA4, handle:0x50C, p
ath:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Psched\Parameters\Winsock"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x717E0000
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0x8000
0005, name:"Mapping", class:0x2, length:0x90, resultlength:0xA4, handle:0x50C, p
ath:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Psched\Parameters\Winsock"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Mapping", class:0x2, length:0xA4, resultlength:0xA4, handle:0x50C, path:"\RE
GISTRY\MACHINE\SYSTEM\ControlSet001\Services\Psched\Parameters\Winsock"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
0C
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x558, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\Curre
ntVersion\Explorer\KindMap"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x50C, access:0x20019, path:"\REGISTRY\MACHINE\SYSTEM\CurrentControlSet\Service
s\Winsock\Setup Migration\Providers"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:".exe", class:0x2, length:0x90, resultlength:0x1C, handle:0x558, path:"\REGIS
TRY\MACHINE\SOFTWARE\MICROSOFT\Windows\CurrentVersion\Explorer\KindMap"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
58
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x504, access:0x20019, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Wi
nsock\Setup Migration\Providers\Psched"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x92, handle:0x386, path:"\REGISTRY\USER\S-1-5-21
-2360094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"WinSock 2.0 Provider ID", class:0x2, length:0x90, resultlength:0x1C, handle:
0x504, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Winsock\Setup Migra
tion\Providers\Psched"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0

x7, length:0x4, resultlength:0x4, handle:0x386, path:"\REGISTRY\USER\S-1-5-21-23


60094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
04
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
0C
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001_Classes\.exe"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x558, access:0x20019, path:"\Registry\Machine\Software\Classes\.exe"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x50C, access:0x20019, path:"\REGISTRY\MACHINE\System\CurrentControlSet\Service
s\Tcpip\Parameters\Winsock"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0x52, handle:0x55A, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\.exe"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Mapping", class:0x2, length:0x90, resultlength:0x74, handle:0x50C, path:"\RE
GISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Winsock"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x55A, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\.exe"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Mapping", class:0x2, length:0x90, resultlength:0x74, handle:0x50C, path:"\RE
GISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Winsock"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
0C
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\.exe"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x50C, access:0x20019, path:"\REGISTRY\MACHINE\SYSTEM\CurrentControlSet\Service
s\Winsock\Setup Migration\Providers"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Content Type", class:0x2, length:0x90, resultlength:0x3E, handle:0x55A, path
:"\REGISTRY\MACHINE\SOFTWARE\Classes\.exe"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
5A
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x504, access:0x20019, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Wi
nsock\Setup Migration\Providers\Tcpip"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"WinSock 2.0 Provider ID", class:0x2, length:0x90, resultlength:0x1C, handle:
0x504, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Winsock\Setup Migra
tion\Providers\Tcpip"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x75670000
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
04
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
0C
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x92, handle:0x386, path:"\REGISTRY\USER\S-1-5-21
-2360094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0

x7, length:0x4, resultlength:0x4, handle:0x386, path:"\REGISTRY\USER\S-1-5-21-23


60094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x50C, access:0x20019, path:"\REGISTRY\MACHINE\System\CurrentControlSet\Service
s\Tcpip\Parameters\Winsock"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001_Classes\.exe"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"MinSockaddrLength", class:0x2, length:0x90, resultlength:0x10, handle:0x50C,
path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Winsock"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x558, access:0x20019, path:"\Registry\Machine\Software\Classes\.exe"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"MaxSockaddrLength", class:0x2, length:0x90, resultlength:0x10, handle:0x50C,
path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Winsock"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0x52, handle:0x55A, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\.exe"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"UseDelayedAcceptance", class:0x2, length:0x90, resultlength:0x10, handle:0x5
0C, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Winso
ck"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x55A, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\.exe"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
0C
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\.exe"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtCreateFile, status:0x0, handl
e:0x50C, access:0xC0140000, iostatus:0x0, information:0x0, attribs:0x0, share:0x
3, disposition:0x3, options:0x0, path:"\Device\Afd\Endpoint"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"", class:0x2, length:0x90, resultlength:0x1C, handle:0x55A, path:"\REGISTRY\
MACHINE\SOFTWARE\Classes\.exe"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x514, iostatus:0x0, information:0x0, code:0x12047, inlen:0xA4, outlen
:0x10, handle:0x50C, path:"\Device\Afd\Endpoint"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x92, handle:0x386, path:"\REGISTRY\USER\S-1-5-21
-2360094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
0C
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x386, path:"\REGISTRY\USER\S-1-5-21-23
60094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtCreateFile, status:0x0, handl
e:0x50C, access:0xC0140000, iostatus:0x0, information:0x0, attribs:0x0, share:0x
3, disposition:0x3, options:0x0, path:"\Device\Afd\Endpoint"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x514, iostatus:0x0, information:0x0, code:0x12047, inlen:0xC4, outlen
:0x1C, handle:0x50C, path:"\Device\Afd\Endpoint"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339

7-2463990887-1001_Classes\exefile"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
0C
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x538, access:0x20019, path:"\Registry\Machine\Software\Classes\exefile"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"C:\WINDOWS\System32\mswsock.dll", handle:0x73700000
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x58, handle:0x53A, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\exefile"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x73700000, name:"NSPStartup", ordinal:0x0, address:0x7370B
530, image:0x0, caller:0x775F615C
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x53A, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\exefile"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x73700000
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_Classes\exefile\CurVer"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\exefile\CurVe
r"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtCreateKey, status:0x0, handle
:0x504, access:0x20019, title:0x0, class:"Class", options:0x0, disposition:0x2,
path:"\REGISTRY\MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x58, handle:0x53A, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\exefile"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x53A, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\exefile"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x508, access:0x20019, path:"\REGISTRY\MACHINE\System\CurrentControlSet\Service
s\DnsCache\Parameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001_Classes\exefile"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies\Microsof
t\Windows NT\DnsClient"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x574, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\exefile\"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Hostname", class:0x2, length:0x90, resultlength:0x2C, handle:0x504, path:"\R
EGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
3A
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Hostname", class:0x2, length:0x90, resultlength:0x2C, handle:0x504, path:"\R
EGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters"

pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0


x3, length:0x188, resultlength:0x58, handle:0x576, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\exefile"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
04
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x576, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\exefile"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
08
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\exefile"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"IsShortcut", class:0x2, length:0x90, resultlength:0x124B208, handle:
0x576, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\exefile"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtCreateKey, status:0x0, handle
:0x508, access:0x20019, title:0x0, class:"Class", options:0x0, disposition:0x2,
path:"\REGISTRY\MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x58, handle:0x576, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\exefile"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x576, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\exefile"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x504, access:0x20019, path:"\REGISTRY\MACHINE\System\CurrentControlSet\Service
s\DnsCache\Parameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies\Microsof
t\Windows NT\DnsClient"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001_Classes\exefile\shell\open"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Hostname", class:0x2, length:0x90, resultlength:0x2C, handle:0x508, path:"\R
EGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x538, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\exefile\shell\o
pen"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Hostname", class:0x2, length:0x90, resultlength:0x2C, handle:0x508, path:"\R
EGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
08
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
04
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x6E, handle:0x53A, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\exefile\shell\open"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtCreateKey, status:0x0, handle
:0x504, access:0x20019, title:0x0, class:"Class", options:0x0, disposition:0x2,

path:"\REGISTRY\MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x53A, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\exefile\shell\open"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x508, access:0x20019, path:"\REGISTRY\MACHINE\System\CurrentControlSet\Service
s\DnsCache\Parameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001_Classes\exefile\shell\open"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies\Microsof
t\Windows NT\DnsClient"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x560, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\exefile\shell\o
pen\"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\Software\Policies\Microsoft\Sy
stem\DNSClient"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x6E, handle:0x562, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\exefile\shell\open"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Domain", class:0x2, length:0x90, resultlength:0xE, handle:0x504, path:"\REGI
STRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x562, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\exefile\shell\open"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Domain", class:0x2, length:0x90, resultlength:0xE, handle:0x504, path:"\REGI
STRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
04
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
08
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001_Classes\exefile\shell\open"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x564, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\exefile\shell\o
pen\"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:DnsQueryEx, status:0x57
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
62
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:New_NtQueryInformationToken::<
lambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x53C,
class:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
53C
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtCreateKey, status:0x0, handle
:0x508, access:0x20019, title:0x0, class:"Class", options:0x0, disposition:0x2,
path:"\REGISTRY\MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters"

pid:4092, tid:11200, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC000002


2, handle:0x0, access:0xF003F, path:"\REGISTRY\MACHINE\System\CurrentControlSet\
Services\WinSock2\Parameters"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x504, access:0x20019, path:"\REGISTRY\MACHINE\System\CurrentControlSet\Service
s\DnsCache\Parameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\Software\Policies\Microsoft\Wi
ndows\Explorer"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handl
e:0x53C, access:0x20019, path:"\REGISTRY\MACHINE\System\CurrentControlSet\Servic
es\WinSock2\Parameters"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies\Microsof
t\Windows NT\DnsClient"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\Software\Policies\Microsoft\Windows\Explorer"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Hostname", class:0x2, length:0x90, resultlength:0x2C, handle:0x508, path:"\R
EGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, n
ame:"WinSock_Registry_Version", class:0x2, length:0x90, resultlength:0x14, handl
e:0x53C, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Paramete
rs"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Hostname", class:0x2, length:0x90, resultlength:0x2C, handle:0x508, path:"\R
EGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x560, c
lass:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
08
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, n
ame:"WinSock_Registry_Version", class:0x2, length:0x90, resultlength:0x14, handl
e:0x53C, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Paramete
rs"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
04
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, n
ame:"AutodialDLL", class:0x2, length:0x90, resultlength:0x4E, handle:0x53C, path
:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtCreateKey, status:0x0, handle
:0x504, access:0x20019, title:0x0, class:"Class", options:0x0, disposition:0x2,
path:"\REGISTRY\MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x57C, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\Curre
ntVersion\Explorer\FolderDescriptions"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, n
ame:"AutodialDLL", class:0x2, length:0x90, resultlength:0x4E, handle:0x53C, path
:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x508, access:0x20019, path:"\REGISTRY\MACHINE\System\CurrentControlSet\Service
s\DnsCache\Parameters"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
53C
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x580, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\W
indows\CurrentVersion\Explorer\FolderDescriptions\{625B53C3-AB48-4EC1-BA1F-A1EF4
146FC19}"

pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5


7C
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies\Microsof
t\Windows NT\DnsClient"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Category", class:0x2, length:0x90, resultlength:0x10, handle:0x580, path:"\R
EGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\F
olderDescriptions\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Name", class:0x2, length:0x90, resultlength:0x22, handle:0x580, path:"\REGIS
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Folde
rDescriptions\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\Software\Policies\Microsoft\Sy
stem\DNSClient"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ParentFolder", class:0x2, length:0x90, resultlength:0x5A, handle:0x580, path
:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explor
er\FolderDescriptions\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Domain", class:0x2, length:0x90, resultlength:0xE, handle:0x504, path:"\REGI
STRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Description", class:0x2, length:0x90, resultlength:0x5A, handle:0x58
0, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion
\Explorer\FolderDescriptions\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Domain", class:0x2, length:0x90, resultlength:0xE, handle:0x504, path:"\REGI
STRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters"
pid:4092, tid:11200, tick:0x33D701E, lvl:LOG, func:NtOpenSection, status:0xC0000
034, handle:0x0, access:0xF, path:"\KnownDlls32\rasadhlp.dll"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"RelativePath", class:0x2, length:0x90, resultlength:0x46, handle:0x580, path
:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explor
er\FolderDescriptions\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
04
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
08
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"ParsingName", class:0x2, length:0x90, resultlength:0x46, handle:0x58
0, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion
\Explorer\FolderDescriptions\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"InfoTip", class:0x2, length:0x90, resultlength:0x46, handle:0x580, p
ath:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Exp
lorer\FolderDescriptions\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"LocalizedName", class:0x2, length:0x90, resultlength:0x60, handle:0x580, pat
h:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explo
rer\FolderDescriptions\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Icon", class:0x2, length:0x90, resultlength:0x60, handle:0x580, path
:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explor
er\FolderDescriptions\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtCreateKey, status:0x0, handle
:0x508, access:0x20019, title:0x0, class:"Class", options:0x0, disposition:0x2,
path:"\REGISTRY\MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000

0034, name:"Security", class:0x2, length:0x90, resultlength:0x60, handle:0x580,


path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Ex
plorer\FolderDescriptions\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtQueryAttributesFile, status:
0x0, attribs:0x20, path:"C:\Windows\System32\rasadhlp.dll"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"StreamResource", class:0x2, length:0x90, resultlength:0x60, handle:0
x580, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVers
ion\Explorer\FolderDescriptions\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x504, access:0x20019, path:"\REGISTRY\MACHINE\System\CurrentControlSet\Service
s\DnsCache\Parameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"StreamResourceType", class:0x2, length:0x90, resultlength:0x60, hand
le:0x580, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Current
Version\Explorer\FolderDescriptions\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"LocalRedirectOnly", class:0x2, length:0x90, resultlength:0x60, handl
e:0x580, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentV
ersion\Explorer\FolderDescriptions\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies\Microsof
t\Windows NT\DnsClient"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Roamable", class:0x2, length:0x90, resultlength:0x60, handle:0x580,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Ex
plorer\FolderDescriptions\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Hostname", class:0x2, length:0x90, resultlength:0x2C, handle:0x508, path:"\R
EGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"PreCreate", class:0x2, length:0x90, resultlength:0x10, handle:0x580, path:"\
REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\
FolderDescriptions\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Hostname", class:0x2, length:0x90, resultlength:0x2C, handle:0x508, path:"\R
EGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Stream", class:0x2, length:0x90, resultlength:0x10, handle:0x580, pa
th:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Expl
orer\FolderDescriptions\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
08
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"PublishExpandedPath", class:0x2, length:0x90, resultlength:0x10, han
dle:0x580, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Curren
tVersion\Explorer\FolderDescriptions\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
04
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DefinitionFlags", class:0x2, length:0x90, resultlength:0x10, handle:
0x580, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVer
sion\Explorer\FolderDescriptions\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Attributes", class:0x2, length:0x90, resultlength:0x10, handle:0x580, path:"
\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer
\FolderDescriptions\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtOpenFile, status:0x0, handle
:0x53C, access:0x100021, iostatus:0x0, information:0x1, share:0x5, options:0x60,
path:"C:\Windows\System32\rasadhlp.dll"

pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtCreateKey, status:0x0, handle


:0x504, access:0x20019, title:0x0, class:"Class", options:0x0, disposition:0x2,
path:"\REGISTRY\MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"FolderTypeID", class:0x2, length:0x90, resultlength:0x10, handle:0x5
80, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersio
n\Explorer\FolderDescriptions\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtCreateSection, status:0x0, h
andle:0x548, access:0xF, pageattribs:0x10, sectionattribs:0x1000000, file:0x53C
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"InitFolderHandler", class:0x2, length:0x90, resultlength:0x10, handl
e:0x580, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentV
ersion\Explorer\FolderDescriptions\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x508, access:0x20019, path:"\REGISTRY\MACHINE\System\CurrentControlSet\Service
s\DnsCache\Parameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Micro
soft\Windows\CurrentVersion\Explorer\FolderDescriptions\{625B53C3-AB48-4EC1-BA1F
-A1EF4146FC19}\PropertyBag"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies\Microsof
t\Windows NT\DnsClient"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtMapViewOfSection, status:0x0
, address:0x6EFD0000, zerobits:0x0, commitsize:0x0, viewsize:0x8000, disposition
:0x1, type:0x800000, protect:0x4, handle:0x548, path:"C:\Windows\System32\rasadh
lp.dll"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
80
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\System\CurrentControlSet\Servi
ces\DNS"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"QueryAdapterName", class:0x2, length:0x90, resultlength:0x5, handle:
0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters
"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DisableAdapterDomainName", class:0x2, length:0x90, resultlength:0xE,
handle:0x504, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Param
eters"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x580, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24639908
87-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"UseDomainNameDevolution", class:0x2, length:0x90, resultlength:0x5,
handle:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Par
ameters"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"UseDomainNameDevolution", class:0x2, length:0x90, resultlength:0x10, handle:
0x504, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\K
nownFolders"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
548
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DomainNameDevolutionLevel", class:0x2, length:0x90, resultlength:0x1
0, handle:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\
Parameters"

pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5


80
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"PrioritizeRecordData", class:0x2, length:0x90, resultlength:0x10, ha
ndle:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Param
eters"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
53C
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"PrioritizeRecordData", class:0x2, length:0x90, resultlength:0x10, ha
ndle:0x504, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Paramete
rs"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"AllowUnqualifiedQuery", class:0x2, length:0x90, resultlength:0x10, h
andle:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Para
meters"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:LdrLoadDll, status:0x0, flags:
0x0, module:"C:\Windows\System32\rasadhlp.dll", handle:0x6EFD0000
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"AllowUnqualifiedQuery", class:0x2, length:0x90, resultlength:0x10, h
andle:0x504, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Paramet
ers"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:LdrGetProcedureAddressForCalle
r, status:0x0, module:0x6EFD0000, name:"WSAttemptAutodialAddr", ordinal:0x0, add
ress:0x6EFD26E0, image:0x0, caller:0x775F5F74
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"AppendToMultiLabelName", class:0x2, length:0x90, resultlength:0x10,
handle:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Par
ameters"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:LdrGetProcedureAddressForCalle
r, status:0x0, module:0x6EFD0000, name:"WSAttemptAutodialName", ordinal:0x0, add
ress:0x6EFD1500, image:0x0, caller:0x775F5F8A
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"ScreenBadTlds", class:0x2, length:0x90, resultlength:0x10, handle:0x
508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x57C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246399
0887-1001"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:LdrGetProcedureAddressForCalle
r, status:0x0, module:0x6EFD0000, name:"WSNoteSuccessfulHostentLookup", ordinal:
0x0, address:0x6EFD27C0, image:0x0, caller:0x775F5FA0
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"ScreenUnreachableServers", class:0x2, length:0x90, resultlength:0x10
, handle:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\P
arameters"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"ScreenDefaultServers", class:0x2, length:0x90, resultlength:0x10, ha
ndle:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Param
eters"
pid:4092, tid:11200, tick:0x33D701E, lvl:LOG, func:NtCreateFile, status:0xC00000
34, handle:0x0, access:0x3, iostatus:0x31DF534, information:0x14, attribs:0x80,
share:0x3, disposition:0x3, options:0x0, path:"\Device\RasAcd"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DynamicServerQueryOrder", class:0x2, length:0x90, resultlength:0x10,
handle:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Pa
rameters"

pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle


:0x584, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folder
s"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"FilterClusterIp", class:0x2, length:0x90, resultlength:0x10, handle:
0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters
"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtDuplicateObject, status:0x0,
targethandle:0x568, access:0x0, inherit:0x0, options:0x2, handle:0xFFFFFFFE
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
7C
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"WaitForNameErrorOnAll", class:0x2, length:0x90, resultlength:0x10, h
andle:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Para
meters"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Start Menu", class:0x2, length:0x90, resultlength:0x82, handle:0x584, path:"
\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft
\Windows\CurrentVersion\Explorer\User Shell Folders"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"UseEdns", class:0x2, length:0x90, resultlength:0x10, handle:0x508, p
ath:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DnsSecureNameQueryFallback", class:0x2, length:0x90, resultlength:0x
10, handle:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache
\Parameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
60
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
84
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"EnableDAForAllNetworks", class:0x2, length:0x90, resultlength:0x10,
handle:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Par
ameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x584, c
lass:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DirectAccessQueryOrder", class:0x2, length:0x90, resultlength:0x10,
handle:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Par
ameters"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"QueryIpMatching", class:0x2, length:0x90, resultlength:0x10, handle:
0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters
"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"UseHostsFile", class:0x2, length:0x90, resultlength:0x10, handle:0x5
08, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x560, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\Curre
ntVersion\Explorer\FolderDescriptions"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"AddrConfigControl", class:0x2, length:0x90, resultlength:0x10, handl
e:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Paramete
rs"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x57C, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\W
indows\CurrentVersion\Explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8
BE3B067}"

pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000


0034, name:"DisableSmartNameResolution", class:0x2, length:0x90, resultlength:0x
10, handle:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache
\Parameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
60
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"PreferLocalOverLowerBindingDNS", class:0x2, length:0x90, resultlengt
h:0x10, handle:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnsc
ache\Parameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Category", class:0x2, length:0x90, resultlength:0x10, handle:0x57C, path:"\R
EGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\F
olderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"QueryNetBTFQDN", class:0x2, length:0x90, resultlength:0x10, handle:0
x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Name", class:0x2, length:0x90, resultlength:0x30, handle:0x57C, path:"\REGIS
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Folde
rDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DisableSmartProtocolReordering", class:0x2, length:0x90, resultlengt
h:0x10, handle:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnsc
ache\Parameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ParentFolder", class:0x2, length:0x90, resultlength:0x5A, handle:0x57C, path
:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explor
er\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"UdpRecvBufferSize", class:0x2, length:0x90, resultlength:0x10, handl
e:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Paramete
rs"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Description", class:0x2, length:0x90, resultlength:0x5A, handle:0x57
C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion
\Explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DisableParallelAandAAAA", class:0x2, length:0x90, resultlength:0x10,
handle:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Pa
rameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"RelativePath", class:0x2, length:0x90, resultlength:0x46, handle:0x57C, path
:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explor
er\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DisableCoalescing", class:0x2, length:0x90, resultlength:0x10, handl
e:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Paramete
rs"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"ParsingName", class:0x2, length:0x90, resultlength:0x46, handle:0x57
C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion
\Explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"FilterVPNTrigger", class:0x2, length:0x90, resultlength:0x10, handle
:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameter
s"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"InfoTip", class:0x2, length:0x90, resultlength:0x46, handle:0x57C, p
ath:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Exp

lorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"EnableMultiHomedRouteConflicts", class:0x2, length:0x90, resultlengt
h:0x10, handle:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnsc
ache\Parameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"LocalizedName", class:0x2, length:0x90, resultlength:0x60, handle:0x57C, pat
h:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explo
rer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"RegistrationEnabled", class:0x2, length:0x90, resultlength:0x10, han
dle:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parame
ters"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Icon", class:0x2, length:0x90, resultlength:0x60, handle:0x57C, path
:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explor
er\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DisableDynamicUpdate", class:0x2, length:0x90, resultlength:0xE, han
dle:0x504, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameter
s"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Security", class:0x2, length:0x90, resultlength:0x60, handle:0x57C,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Ex
plorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"RegisterPrimaryName", class:0x2, length:0x90, resultlength:0x10, han
dle:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parame
ters"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"StreamResource", class:0x2, length:0x90, resultlength:0x60, handle:0
x57C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVers
ion\Explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"RegisterAdapterName", class:0x2, length:0x90, resultlength:0x10, han
dle:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parame
ters"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"StreamResourceType", class:0x2, length:0x90, resultlength:0x60, hand
le:0x57C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Current
Version\Explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"EnableAdapterDomainNameRegistration", class:0x2, length:0x90, result
length:0xE, handle:0x504, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\
Tcpip\Parameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"LocalRedirectOnly", class:0x2, length:0x90, resultlength:0x60, handl
e:0x57C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentV
ersion\Explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"RegisterReverseLookup", class:0x2, length:0x90, resultlength:0x10, h
andle:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Para
meters"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Roamable", class:0x2, length:0x90, resultlength:0x60, handle:0x57C,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Ex
plorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DisableReverseAddressRegistrations", class:0x2, length:0x90, resultl
ength:0xE, handle:0x504, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\T

cpip\Parameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"PreCreate", class:0x2, length:0x90, resultlength:0x10, handle:0x57C, path:"\
REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\
FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"RegisterWanAdapters", class:0x2, length:0x90, resultlength:0x10, han
dle:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parame
ters"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Stream", class:0x2, length:0x90, resultlength:0x10, handle:0x57C, pa
th:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Expl
orer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DisableWanDynamicUpdate", class:0x2, length:0x90, resultlength:0xE,
handle:0x504, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parame
ters"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"PublishExpandedPath", class:0x2, length:0x90, resultlength:0x10, han
dle:0x57C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Curren
tVersion\Explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"RegistrationTtl", class:0x2, length:0x90, resultlength:0x10, handle:
0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters
"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DefinitionFlags", class:0x2, length:0x90, resultlength:0x10, handle:
0x57C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVer
sion\Explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DefaultRegistrationTTL", class:0x2, length:0x90, resultlength:0xE, h
andle:0x504, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Paramet
ers"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Attributes", class:0x2, length:0x90, resultlength:0x10, handle:0x57C, path:"
\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer
\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"RegistrationRefreshInterval", class:0x2, length:0x90, resultlength:0
x10, handle:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscach
e\Parameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"FolderTypeID", class:0x2, length:0x90, resultlength:0x10, handle:0x5
7C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersio
n\Explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DefaultRegistrationRefreshInterval", class:0x2, length:0x90, resultl
ength:0xE, handle:0x504, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\T
cpip\Parameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"InitFolderHandler", class:0x2, length:0x90, resultlength:0x10, handl
e:0x57C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentV
ersion\Explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"RegistrationMaxAddressCount", class:0x2, length:0x90, resultlength:0
x10, handle:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscach
e\Parameters"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"MaxNumberOfAddressesToRegister", class:0x2, length:0x90, resultlengt
h:0xE, handle:0x504, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip

\Parameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Micro
soft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C
-E74B8BE3B067}\PropertyBag"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
7C
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"UpdateSecurityLevel", class:0x2, length:0x90, resultlength:0x10, han
dle:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parame
ters"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"UpdateSecurityLevel", class:0x2, length:0x90, resultlength:0x10, han
dle:0x504, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameter
s"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"UpdateTopLevelDomainZones", class:0x2, length:0x90, resultlength:0x1
0, handle:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\
Parameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x57C, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24639908
87-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DowncaseSpnCauseApiOwnerIsTooLazy", class:0x2, length:0x90, resultle
ngth:0x10, handle:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\D
nscache\Parameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\K
nownFolders"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"RegistrationOverwrite", class:0x2, length:0x90, resultlength:0x10, h
andle:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Para
meters"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
7C
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"MaxCacheSize", class:0x2, length:0x90, resultlength:0x10, handle:0x5
08, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"MaxCacheTtl", class:0x2, length:0x90, resultlength:0x10, handle:0x50
8, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x57C, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\Curre
ntVersion\Explorer\User Shell Folders"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"MaxNegativeCacheTtl", class:0x2, length:0x90, resultlength:0x10, han
dle:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parame
ters"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"AdapterTimeoutLimit", class:0x2, length:0x90, resultlength:0x10, han
dle:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parame
ters"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Common Start Menu", class:0x2, length:0x90, resultlength:0x62, handle:0x57C,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\E
xplorer\User Shell Folders"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"ServerPriorityTimeLimit", class:0x2, length:0x90, resultlength:0x10,
handle:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Pa

rameters"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"MaxCachedSockets", class:0x2, length:0x90, resultlength:0x10, handle
:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameter
s"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
84
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DisableServerUnreachability", class:0x2, length:0x90, resultlength:0
x10, handle:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscach
e\Parameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
7C
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"EnableMulticast", class:0x2, length:0x90, resultlength:0x10, handle:
0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters
"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x57C, c
lass:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"MulticastResponderFlags", class:0x2, length:0x90, resultlength:0x10,
handle:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Pa
rameters"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"MulticastSenderFlags", class:0x2, length:0x90, resultlength:0x10, ha
ndle:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Param
eters"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x584, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\Curre
ntVersion\Explorer\FolderDescriptions"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"MulticastSenderMaxTimeout", class:0x2, length:0x90, resultlength:0x1
0, handle:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\
Parameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x560, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\W
indows\CurrentVersion\Explorer\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092
E34987A}"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
84
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DnsTest", class:0x2, length:0x90, resultlength:0x10, handle:0x508, p
ath:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Category", class:0x2, length:0x90, resultlength:0x10, handle:0x560, path:"\R
EGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\F
olderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"UseCompartments", class:0x2, length:0x90, resultlength:0x10, handle:
0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters
"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Name", class:0x2, length:0x90, resultlength:0x1A, handle:0x560, path:"\REGIS
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Folde
rDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"CacheAllCompartments", class:0x2, length:0x90, resultlength:0x10, ha
ndle:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Param
eters"

pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na


me:"ParentFolder", class:0x2, length:0x90, resultlength:0x5A, handle:0x560, path
:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explor
er\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"UseNewRegistration", class:0x2, length:0x90, resultlength:0x10, hand
le:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Paramet
ers"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Description", class:0x2, length:0x90, resultlength:0x5A, handle:0x56
0, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion
\Explorer\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"ResolverRegistration", class:0x2, length:0x90, resultlength:0x10, ha
ndle:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Param
eters"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"RelativePath", class:0x2, length:0x90, resultlength:0x3E, handle:0x560, path
:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explor
er\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"ResolverRegistrationOnly", class:0x2, length:0x90, resultlength:0x10
, handle:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\P
arameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"ParsingName", class:0x2, length:0x90, resultlength:0x3E, handle:0x56
0, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion
\Explorer\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"NewDhcpSrvRegistration", class:0x2, length:0x90, resultlength:0x10,
handle:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Par
ameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"InfoTip", class:0x2, length:0x90, resultlength:0x34, handle:0x560, path:"\RE
GISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Fo
lderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DirectAccessPreferLocal", class:0x2, length:0x90, resultlength:0x10,
handle:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Pa
rameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"LocalizedName", class:0x2, length:0x90, resultlength:0x60, handle:0x560, pat
h:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explo
rer\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DisableIdnEncoding", class:0x2, length:0x90, resultlength:0x10, hand
le:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Paramet
ers"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Icon", class:0x2, length:0x90, resultlength:0x5C, handle:0x560, path:"\REGIS
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Folde
rDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"EnableIdnMapping", class:0x2, length:0x90, resultlength:0x10, handle
:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameter
s"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Security", class:0x2, length:0x90, resultlength:0x5C, handle:0x560,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Ex
plorer\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}"

pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000


0034, name:"TestMode_AdaptiveTimeoutHistoryLength", class:0x2, length:0x90, resu
ltlength:0x10, handle:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Servic
es\Dnscache\Parameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"StreamResource", class:0x2, length:0x90, resultlength:0x5C, handle:0
x560, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVers
ion\Explorer\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"TestMode_AdaptiveTimeoutRecalculationInterval", class:0x2, length:0x
90, resultlength:0x10, handle:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet00
1\Services\Dnscache\Parameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"StreamResourceType", class:0x2, length:0x90, resultlength:0x5C, hand
le:0x560, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Current
Version\Explorer\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x580, access:0x1, path:"\REGISTRY\MACHINE\System\Setup"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"LocalRedirectOnly", class:0x2, length:0x90, resultlength:0x5C, handl
e:0x560, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentV
ersion\Explorer\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"SystemSetupInProgress", class:0x2, length:0x90, resultlength:0x10, handle:0x
580, path:"\REGISTRY\MACHINE\SYSTEM\Setup"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Roamable", class:0x2, length:0x90, resultlength:0x5C, handle:0x560,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Ex
plorer\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
80
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"PreCreate", class:0x2, length:0x90, resultlength:0x10, handle:0x560, path:"\
REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\
FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DnsQueryTimeouts", class:0x2, length:0x90, resultlength:0x1258870, h
andle:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Para
meters"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Stream", class:0x2, length:0x90, resultlength:0x10, handle:0x560, pa
th:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Expl
orer\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DnsQueryTimeouts", class:0x2, length:0x90, resultlength:0x1258870, h
andle:0x504, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Paramet
ers"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"PublishExpandedPath", class:0x2, length:0x90, resultlength:0x10, han
dle:0x560, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Curren
tVersion\Explorer\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DnsQuickQueryTimeouts", class:0x2, length:0x90, resultlength:0x12588
70, handle:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache
\Parameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DefinitionFlags", class:0x2, length:0x90, resultlength:0x10, handle:
0x560, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVer
sion\Explorer\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000

0034, name:"DnsQuickQueryTimeouts", class:0x2, length:0x90, resultlength:0x12588


70, handle:0x504, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Pa
rameters"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
04
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Attributes", class:0x2, length:0x90, resultlength:0x10, handle:0x560, path:"
\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer
\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
08
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"FolderTypeID", class:0x2, length:0x90, resultlength:0x10, handle:0x5
60, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersio
n\Explorer\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x72170000
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"InitFolderHandler", class:0x2, length:0x90, resultlength:0x10, handl
e:0x560, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentV
ersion\Explorer\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x508, iostatus:0x0, information:0x50, code:0x120007, inlen:0x30, outl
en:0x4, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Micro
soft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AE50C081-EBD2-438A-8655
-8A092E34987A}\PropertyBag"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
08
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
60
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x560, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24639908
87-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\K
nownFolders"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
60
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:DnsQueryEx, status:0x0
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x588, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246399
0887-1001"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x58C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folder
s"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
88
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Recent", class:0x2, length:0x90, resultlength:0x7A, handle:0x58C, path:"\REG
ISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Win
dows\CurrentVersion\Explorer\User Shell Folders"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtOpenSection, status:0xC00000

34, handle:0x0, access:0xF, path:"\KnownDlls32\fwpuclnt.dll"


pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
7C
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
8C
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x58C, c
lass:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x57C, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\Curre
ntVersion\Explorer\FolderDescriptions"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x560, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\W
indows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0
B28FC23}"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
7C
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x20, path:"C:\WINDOWS\System32\fwpuclnt.dll"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Category", class:0x2, length:0x90, resultlength:0x10, handle:0x560, path:"\R
EGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\F
olderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Name", class:0x2, length:0x90, resultlength:0x1C, handle:0x560, path:"\REGIS
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Folde
rDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"ParentFolder", class:0x2, length:0x90, resultlength:0x10, handle:0x5
60, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersio
n\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Description", class:0x2, length:0x90, resultlength:0x10, handle:0x56
0, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion
\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"RelativePath", class:0x2, length:0x90, resultlength:0x10, handle:0x5
60, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersio
n\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"ParsingName", class:0x2, length:0x90, resultlength:0x10, handle:0x56
0, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion
\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"InfoTip", class:0x2, length:0x90, resultlength:0x10, handle:0x560, p
ath:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Exp
lorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"LocalizedName", class:0x2, length:0x90, resultlength:0x10, handle:0x
560, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersi
on\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtOpenFile, status:0x0, handle:
0x53C, access:0x100021, iostatus:0x0, information:0x1, share:0x5, options:0x60,
path:"C:\WINDOWS\System32\fwpuclnt.dll"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Icon", class:0x2, length:0x90, resultlength:0x10, handle:0x560, path
:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explor
er\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtCreateSection, status:0x0, ha
ndle:0x548, access:0xF, pageattribs:0x10, sectionattribs:0x1000000, file:0x53C

pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000


0034, name:"Security", class:0x2, length:0x90, resultlength:0x10, handle:0x560,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Ex
plorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"StreamResource", class:0x2, length:0x90, resultlength:0x10, handle:0
x560, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVers
ion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x6EFE0000, zerobits:0x0, commitsize:0x0, viewsize:0x47000, disposition
:0x1, type:0x800000, protect:0x4, handle:0x548, path:"C:\WINDOWS\System32\fwpucl
nt.dll"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"StreamResourceType", class:0x2, length:0x90, resultlength:0x10, hand
le:0x560, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Current
Version\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"LocalRedirectOnly", class:0x2, length:0x90, resultlength:0x10, handl
e:0x560, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentV
ersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Roamable", class:0x2, length:0x90, resultlength:0x10, handle:0x560,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Ex
plorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"PreCreate", class:0x2, length:0x90, resultlength:0x10, handle:0x560,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\E
xplorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Stream", class:0x2, length:0x90, resultlength:0x10, handle:0x560, pa
th:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Expl
orer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}"
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
48
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"PublishExpandedPath", class:0x2, length:0x90, resultlength:0x10, han
dle:0x560, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Curren
tVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DefinitionFlags", class:0x2, length:0x90, resultlength:0x10, handle:
0x560, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVer
sion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}"
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
3C
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Attributes", class:0x2, length:0x90, resultlength:0x10, handle:0x560
, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\
Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"FolderTypeID", class:0x2, length:0x90, resultlength:0x10, handle:0x5
60, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersio
n\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"InitFolderHandler", class:0x2, length:0x90, resultlength:0x10, handl
e:0x560, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentV
ersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x510, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\W
indows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0
B28FC23}\PropertyBag"

pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5


60
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x53C, access:0x9, path:"\Registry\Machine\SYSTEM\CurrentControlSet\Control\Sessi
on Manager"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
8C
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x58C, c
lass:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:8264, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"ResourcePolicies", class:0x2, length:0x18, resultlength:0x0, handle:
0x53C, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\SESSION MANAGER"
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
3C
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x560, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\Curre
ntVersion\Explorer\FolderDescriptions"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x530, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\W
indows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1A
E5198B7}"
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtCreateSemaphore, status:0x0,
handle:0x508, access:0x1F0003, initialcount:0x0, maxcount:0x1
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
60
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"C:\WINDOWS\System32\fwpuclnt.dll", handle:0x6EFE0000
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Category", class:0x2, length:0x90, resultlength:0x10, handle:0x530, path:"\R
EGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\F
olderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Name", class:0x2, length:0x90, resultlength:0x1A, handle:0x530, path:"\REGIS
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Folde
rDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}"
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x6EFE0000, name:"NamespaceCallout", ordinal:0x0, address:0
x6EFF2070, image:0x0, caller:0x775F9787
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"ParentFolder", class:0x2, length:0x90, resultlength:0x10, handle:0x5
30, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersio
n\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}"
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x4E0, c
lass:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x4
E0
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Description", class:0x2, length:0x90, resultlength:0x10, handle:0x53
0, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion
\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"RelativePath", class:0x2, length:0x90, resultlength:0x10, handle:0x5
30, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersio
n\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"ParsingName", class:0x2, length:0x90, resultlength:0x10, handle:0x53
0, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion
\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}"

pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000


0034, name:"InfoTip", class:0x2, length:0x90, resultlength:0x10, handle:0x530, p
ath:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Exp
lorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"LocalizedName", class:0x2, length:0x90, resultlength:0x10, handle:0x
530, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersi
on\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}"
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Icon", class:0x2, length:0x90, resultlength:0x10, handle:0x530, path
:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explor
er\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Security", class:0x2, length:0x90, resultlength:0x10, handle:0x530,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Ex
plorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"StreamResource", class:0x2, length:0x90, resultlength:0x10, handle:0
x530, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVers
ion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"StreamResourceType", class:0x2, length:0x90, resultlength:0x10, hand
le:0x530, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Current
Version\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"LocalRedirectOnly", class:0x2, length:0x90, resultlength:0x10, handl
e:0x530, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentV
ersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Roamable", class:0x2, length:0x90, resultlength:0x10, handle:0x530,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Ex
plorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"PreCreate", class:0x2, length:0x90, resultlength:0x10, handle:0x530,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\E
xplorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Stream", class:0x2, length:0x90, resultlength:0x10, handle:0x530, pa
th:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Expl
orer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"PublishExpandedPath", class:0x2, length:0x90, resultlength:0x10, han
dle:0x530, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Curren
tVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DefinitionFlags", class:0x2, length:0x90, resultlength:0x10, handle:
0x530, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVer
sion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Attributes", class:0x2, length:0x90, resultlength:0x10, handle:0x530
, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\
Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"FolderTypeID", class:0x2, length:0x90, resultlength:0x10, handle:0x5
30, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersio
n\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000

0034, name:"InitFolderHandler", class:0x2, length:0x90, resultlength:0x10, handl


e:0x530, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentV
ersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x57C, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\W
indows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1A
E5198B7}\PropertyBag"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
30
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
8C
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtOpenEvent, status:0x0, handle
:0x53C, access:0x100000, path:"\Sessions\1\BaseNamedObjects\Global\BFE_Notify_Ev
ent_{a3a05c3b-90ae-4c3e-959c-1c8a488d7c6f}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x58C, c
lass:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
3C
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x530, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\Curre
ntVersion\Explorer\FolderDescriptions"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x588, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\W
indows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C854
80369C7}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
30
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
5C
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Category", class:0x2, length:0x90, resultlength:0x10, handle:0x588, path:"\R
EGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\F
olderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Name", class:0x2, length:0x90, resultlength:0x1E, handle:0x588, path:"\REGIS
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Folde
rDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"ParentFolder", class:0x2, length:0x90, resultlength:0x10, handle:0x5
88, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersio
n\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Description", class:0x2, length:0x90, resultlength:0x10, handle:0x58
8, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion
\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"RelativePath", class:0x2, length:0x90, resultlength:0x20, handle:0x588, path
:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explor
er\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}"
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtCreateFile, status:0x0, handl
e:0x55C, access:0xC0140000, iostatus:0x0, information:0x0, attribs:0x0, share:0x
3, disposition:0x3, options:0x0, path:"\Device\Afd\Endpoint"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0x8000
0005, name:"ParsingName", class:0x2, length:0x90, resultlength:0xBC, handle:0x58
8, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion
\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}"
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x514, iostatus:0x0, information:0x0, code:0x12047, inlen:0xC4, outlen
:0x1C, handle:0x55C, path:"\Device\Afd\Endpoint"

pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryValueKey, status:0x0, na


me:"ParsingName", class:0x2, length:0xBC, resultlength:0xBC, handle:0x588, path:
"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explore
r\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"InfoTip", class:0x2, length:0x90, resultlength:0xBC, handle:0x588, p
ath:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Exp
lorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}"
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtDeviceIoControlFile, status:0
x103, event:0x514, iostatus:0x0, information:0xC, code:0x120BF, inlen:0x18, outl
en:0xC, handle:0x55C, path:"\Device\Afd\Endpoint"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"LocalizedName", class:0x2, length:0x90, resultlength:0x70, handle:0x588, pat
h:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explo
rer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}"
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
5C
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Icon", class:0x2, length:0x90, resultlength:0x5C, handle:0x588, path:"\REGIS
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Folde
rDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}"
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
0C
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Security", class:0x2, length:0x90, resultlength:0x5C, handle:0x588,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Ex
plorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"StreamResource", class:0x2, length:0x90, resultlength:0x5C, handle:0
x588, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVers
ion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}"
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"C:\WINDOWS\system32\ws2_32", handle:0x775F0000
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"StreamResourceType", class:0x2, length:0x90, resultlength:0x5C, hand
le:0x588, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Current
Version\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}"
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x775F0000, name:"getaddrinfo", ordinal:0x0, address:0x7760
5B80, image:0x0, caller:0x70303743
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x775F0000, name:"getaddrinfo", ordinal:0x0, address:0x7760
5B80, image:0x0, caller:0x70303763
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"LocalRedirectOnly", class:0x2, length:0x90, resultlength:0x5C, handl
e:0x588, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentV
ersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}"
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x775F0000, name:"getnameinfo", ordinal:0x0, address:0x7760
4C90, image:0x0, caller:0x70303763
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x775F0000, name:"freeaddrinfo", ordinal:0x0, address:0x776
064A0, image:0x0, caller:0x70303763
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Roamable", class:0x2, length:0x90, resultlength:0x10, handle:0x588, path:"\R
EGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\F
olderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"PreCreate", class:0x2, length:0x90, resultlength:0x10, handle:0x588, path:"\
REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\

FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Stream", class:0x2, length:0x90, resultlength:0x10, handle:0x588, pa
th:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Expl
orer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}"
pid:4092, tid:1488, tick:0x33D702E, lvl:OK, func:NtDuplicateObject, status:0x0,
targethandle:0x4E0, access:0x0, inherit:0x0, options:0x2, handle:0xFFFFFFFE
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"PublishExpandedPath", class:0x2, length:0x90, resultlength:0x10, han
dle:0x588, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Curren
tVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DefinitionFlags", class:0x2, length:0x90, resultlength:0x10, handle:
0x588, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVer
sion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}"
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtCreateFile, status:0x0, handl
e:0x55C, access:0xC0140000, iostatus:0x0, information:0x0, attribs:0x0, share:0x
3, disposition:0x3, options:0x0, path:"\Device\Afd\Endpoint"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Attributes", class:0x2, length:0x90, resultlength:0x10, handle:0x588, path:"
\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer
\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}"
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x514, iostatus:0x0, information:0x0, code:0x12047, inlen:0xA4, outlen
:0x10, handle:0x55C, path:"\Device\Afd\Endpoint"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"FolderTypeID", class:0x2, length:0x90, resultlength:0x10, handle:0x5
88, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersio
n\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}"
pid:4092, tid:1488, tick:0x33D702E, lvl:OK, func:NtCreateFile, status:0x0, handl
e:0x53C, access:0xC0140000, iostatus:0x0, information:0x0, attribs:0x0, share:0x
3, disposition:0x3, options:0x0, path:"\Device\Afd\Endpoint"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"InitFolderHandler", class:0x2, length:0x90, resultlength:0x10, handl
e:0x588, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentV
ersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}"
pid:4092, tid:1488, tick:0x33D702E, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x50C, iostatus:0x0, information:0x0, code:0x12047, inlen:0xA4, outlen
:0x10, handle:0x53C, path:"\Device\Afd\Endpoint"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x530, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\W
indows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C854
80369C7}\PropertyBag"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
88
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x588, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24639908
87-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\K
nownFolders"
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x20, path:"C:\WINDOWS\System32\mswsock.dll"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
88
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0

pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtQueryVirtualMemory, status:0x


0, address:0x2CCD898, class:0x3, length:0x14
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:LdrUnloadDll, status:0x0, handl
e:0x73700000
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x590, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246399
0887-1001"
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x20, path:"C:\WINDOWS\System32\mswsock.dll"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x594, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folder
s"
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2CCD898, class:0x3, length:0x14
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
90
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:LdrUnloadDll, status:0x0, handl
e:0x73700000
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Personal", class:0x2, length:0x90, resultlength:0x3C, handle:0x594, path:"\R
EGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\W
indows\CurrentVersion\Explorer\User Shell Folders"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
8C
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
94
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x594, c
lass:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x20, path:"C:\WINDOWS\System32\mswsock.dll"
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2CCD898, class:0x3, length:0x14
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x58C, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\Curre
ntVersion\Explorer\FolderDescriptions"
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:LdrUnloadDll, status:0x0, handl
e:0x73700000
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x588, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\W
indows\CurrentVersion\Explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F39
10AB8FE}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
8C
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Category", class:0x2, length:0x90, resultlength:0x10, handle:0x588, path:"\R
EGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\F
olderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Name", class:0x2, length:0x90, resultlength:0x18, handle:0x588, path:"\REGIS
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Folde
rDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ParentFolder", class:0x2, length:0x90, resultlength:0x5A, handle:0x588, path
:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explor
er\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}"
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x20, path:"C:\WINDOWS\System32\mswsock.dll"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000

0034, name:"Description", class:0x2, length:0x90, resultlength:0x5A, handle:0x58


8, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion
\Explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}"
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2CCD898, class:0x3, length:0x14
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"RelativePath", class:0x2, length:0x90, resultlength:0x5A, handle:0x5
88, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersio
n\Explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}"
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:LdrUnloadDll, status:0x0, handl
e:0x73700000
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"ParsingName", class:0x2, length:0x90, resultlength:0x5A, handle:0x58
8, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion
\Explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"InfoTip", class:0x2, length:0x90, resultlength:0x5A, handle:0x588, p
ath:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Exp
lorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"LocalizedName", class:0x2, length:0x90, resultlength:0x5A, handle:0x
588, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersi
on\Explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Icon", class:0x2, length:0x90, resultlength:0x5A, handle:0x588, path
:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explor
er\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Security", class:0x2, length:0x90, resultlength:0x5A, handle:0x588,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Ex
plorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}"
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x20, path:"C:\WINDOWS\System32\mswsock.dll"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"StreamResource", class:0x2, length:0x90, resultlength:0x5A, handle:0
x588, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVers
ion\Explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}"
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2CCD898, class:0x3, length:0x14
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:LdrUnloadDll, status:0x0, handl
e:0x73700000
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"StreamResourceType", class:0x2, length:0x90, resultlength:0x5A, hand
le:0x588, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Current
Version\Explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"LocalRedirectOnly", class:0x2, length:0x90, resultlength:0x5A, handl
e:0x588, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentV
ersion\Explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Roamable", class:0x2, length:0x90, resultlength:0x5A, handle:0x588,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Ex
plorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"PreCreate", class:0x2, length:0x90, resultlength:0x5A, handle:0x588,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\E
xplorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Stream", class:0x2, length:0x90, resultlength:0x5A, handle:0x588, pa
th:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Expl

orer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"PublishExpandedPath", class:0x2, length:0x90, resultlength:0x5A, han
dle:0x588, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Curren
tVersion\Explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}"
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x20, path:"C:\WINDOWS\System32\mswsock.dll"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DefinitionFlags", class:0x2, length:0x90, resultlength:0x5A, handle:
0x588, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVer
sion\Explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}"
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2CCD898, class:0x3, length:0x14
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:LdrUnloadDll, status:0x0, handl
e:0x73700000
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Attributes", class:0x2, length:0x90, resultlength:0x5A, handle:0x588
, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\
Explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"FolderTypeID", class:0x2, length:0x90, resultlength:0x5A, handle:0x5
88, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersio
n\Explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"InitFolderHandler", class:0x2, length:0x90, resultlength:0x5A, handl
e:0x588, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentV
ersion\Explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x58C, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\W
indows\CurrentVersion\Explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F39
10AB8FE}\PropertyBag"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
88
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
94
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x20, path:"C:\WINDOWS\System32\wshqos.dll"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKey, status:0xC0000034,
handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{0000
0323-0000-0000-C000-000000000046}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x594, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Rpc\Extensions"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"NdrOleExtDLL", class:0x2, length:0x21A, resultlength:0x24, handle:0x594, pat
h:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Rpc\Extensions"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
94
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"combase.dll", module:0x74DC0000
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74DC0000, name:"NdrOleInitializeExtension", ordinal:0x0,
address:0x74E96DA0, image:0x0, caller:0x770340A5
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtCreateFile, status:0x0, handl
e:0x580, access:0x80100080, iostatus:0x0, information:0x1, attribs:0x0, share:0x
5, disposition:0x1, options:0x60, path:"C:\WINDOWS\System32\wshqos.dll"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74DC0000, name:"CoGetMarshalSizeMax", ordinal:0x0, addres
s:0x74E45230, image:0x0, caller:0x74E96DFA
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74DC0000, name:"CoMarshalInterface", ordinal:0x0, address

:0x74E45680, image:0x0, caller:0x74E96E18


pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74DC0000, name:"CoUnmarshalInterface", ordinal:0x0, addre
ss:0x74E406A0, image:0x0, caller:0x74E96E36
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtCreateSection, status:0x0, ha
ndle:0x584, access:0x5, pageattribs:0x2, sectionattribs:0x11000000, file:0x580
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74DC0000, name:"StringFromIID", ordinal:0x0, address:0x74
E03710, image:0x0, caller:0x74E96E54
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74DC0000, name:"CoTaskMemAlloc", ordinal:0x0, address:0x7
4E7FAB0, image:0x0, caller:0x74E96E6E
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74DC0000, name:"CoTaskMemFree", ordinal:0x0, address:0x74
E7FBF0, image:0x0, caller:0x74E96E88
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtMapViewOfSection, status:0x40
000003, address:0x5A0000, zerobits:0x0, commitsize:0x0, viewsize:0x8000, disposi
tion:0x1, type:0x800000, protect:0x2, handle:0x584, path:"C:\WINDOWS\System32\ws
hqos.dll"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74DC0000, name:"CoCreateInstance", ordinal:0x0, address:0
x74E39C80, image:0x0, caller:0x74E96EA2
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74DC0000, name:"CoReleaseMarshalData", ordinal:0x0, addre
ss:0x74E10520, image:0x0, caller:0x74E96EBC
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
84
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:CoCreateInstance, hr:0x0, clsid
:00000323-0000-0000-C000-000000000046, context:0x1, riid:00000146-0000-0000-C000
-000000000046
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
80
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FC, class:0x14, length:0x4, returnlength:0x4
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FC, class:0x1A, length:0x4, returnlength:0x4
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2D799A0, class:0x3, length:0x14
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5A0000
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:Init, log:"Dropping DesiredAcc
ess from 0x20119 to 0x20019 for faulting in key \REGISTRY\USER\S-1-5-21-23600946
02-2602383397-2463990887-1001\Software\Spoon\SandboxCache\A527E666CB0D6807\roami
ng\modified\@HKCU@\"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x588, access:0x20119, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246399
0887-1001"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x590, access:0x20119, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Classes\Local Settings"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
88
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339

7-2463990887-1001_CLASSES\Local Settings\Software\Microsoft\Ole\FeatureDevelopme
ntProperties"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
90
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20119, path:"\REGISTRY\MACHINE\Software\Microsoft\Ole\Fea
tureDevelopmentProperties"
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x20, path:"C:\WINDOWS\System32\wshqos.dll"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x74DC0000
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x590, access:0x20119, path:"\Registry\Machine\SOFTWARE\Policies\Microsoft\Window
s\Appx"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"AllowDevelopmentWithoutDevLicense", class:0x2, length:0x18, resultlength:0x1
0, handle:0x590, path:"\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\App
x"
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtCreateFile, status:0x0, handl
e:0x580, access:0x80100080, iostatus:0x0, information:0x1, attribs:0x0, share:0x
5, disposition:0x1, options:0x60, path:"C:\WINDOWS\System32\wshqos.dll"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
90
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtCreateSection, status:0x0, ha
ndle:0x584, access:0x5, pageattribs:0x2, sectionattribs:0x11000000, file:0x580
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x590, access:0x20119, path:"\Registry\Machine\SOFTWARE\Microsoft\Windows\Current
Version\AppModelUnlock"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"AllowDevelopmentWithoutDevLicense", class:0x2, length:0x18, resultle
ngth:0x0, handle:0x590, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Windows\Curre
ntVersion\AppModelUnlock"
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtMapViewOfSection, status:0x40
000003, address:0x5A0000, zerobits:0x0, commitsize:0x0, viewsize:0x8000, disposi
tion:0x1, type:0x800000, protect:0x2, handle:0x584, path:"C:\WINDOWS\System32\ws
hqos.dll"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
90
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
84
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
80
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"ntdll.dll", module:0x77C10000
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2D799A0, class:0x3, length:0x14
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77C10000, name:"NtQuerySystemInformation", ordinal:0x0, a
ddress:0x77C86F30, image:0x0, caller:0x74EA12A1
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5A0000
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x20, path:"C:\WINDOWS\System32\wshqos.dll"
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtCreateFile, status:0x0, handl
e:0x580, access:0x80100080, iostatus:0x0, information:0x1, attribs:0x0, share:0x
5, disposition:0x1, options:0x60, path:"C:\WINDOWS\System32\wshqos.dll"
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtCreateSection, status:0x0, ha
ndle:0x584, access:0x5, pageattribs:0x2, sectionattribs:0x11000000, file:0x580
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtMapViewOfSection, status:0x40
000003, address:0x5A0000, zerobits:0x0, commitsize:0x0, viewsize:0x8000, disposi

tion:0x1, type:0x800000, protect:0x2, handle:0x584, path:"C:\WINDOWS\System32\ws


hqos.dll"
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
84
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
80
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2D799A0, class:0x3, length:0x14
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5A0000
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x20, path:"C:\WINDOWS\System32\wshqos.dll"
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtCreateFile, status:0x0, handl
e:0x580, access:0x80100080, iostatus:0x0, information:0x1, attribs:0x0, share:0x
5, disposition:0x1, options:0x60, path:"C:\WINDOWS\System32\wshqos.dll"
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtCreateSection, status:0x0, ha
ndle:0x584, access:0x5, pageattribs:0x2, sectionattribs:0x11000000, file:0x580
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtMapViewOfSection, status:0x40
000003, address:0x5A0000, zerobits:0x0, commitsize:0x0, viewsize:0x8000, disposi
tion:0x1, type:0x800000, protect:0x2, handle:0x584, path:"C:\WINDOWS\System32\ws
hqos.dll"
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
84
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
80
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2D799A0, class:0x3, length:0x14
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5A0000
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtSetInformationFile, status:0x
0, iostatus:0x0, information:0x0, length:0x4, class:0x29, handle:0x55C, path:"\D
evice\Afd\Endpoint"
pid:4092, tid:1488, tick:0x33D702E, lvl:OK, func:NtSetInformationFile, status:0x
0, iostatus:0x0, information:0x0, length:0x4, class:0x29, handle:0x53C, path:"\D
evice\Afd\Endpoint"
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtSetInformationFile, status:0x
0, iostatus:0x0, information:0x0, length:0x8, class:0x1E, handle:0x55C, path:"\D
evice\Afd\Endpoint"
pid:4092, tid:1488, tick:0x33D702E, lvl:OK, func:NtSetInformationFile, status:0x
0, iostatus:0x0, information:0x0, length:0x8, class:0x1E, handle:0x53C, path:"\D
evice\Afd\Endpoint"
pid:4092, tid:1488, tick:0x33D702E, lvl:OK, func:NtDeviceIoControlFile, status:0
x103, event:0x50C, iostatus:0x0, information:0x10, code:0x12003, inlen:0x14, out
len:0x10, handle:0x53C, path:"\Device\Afd\Endpoint"
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtDeviceIoControlFile, status:0
x103, event:0x514, iostatus:0x0, information:0x10, code:0x12003, inlen:0x14, out
len:0x10, handle:0x55C, path:"\Device\Afd\Endpoint"
pid:4092, tid:1488, tick:0x33D702E, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x50C, iostatus:0x0, information:0x0, code:0x12047, inlen:0xA4, outlen
:0x0, handle:0x53C, path:"\Device\Afd\Endpoint"
pid:4092, tid:1488, tick:0x33D702E, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x50C, iostatus:0x0, information:0x10, code:0x1202F, inlen:0x0, outlen
:0x10, handle:0x53C, path:"\Device\Afd\Endpoint"
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x514, iostatus:0x0, information:0x0, code:0x12047, inlen:0xA4, outlen
:0x0, handle:0x55C, path:"\Device\Afd\Endpoint"
pid:4092, tid:1488, tick:0x33D702E, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x50C, iostatus:0x0, information:0x0, code:0x120BF, inlen:0x18, outlen
:0x0, handle:0x53C, path:"\Device\Afd\Endpoint"
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtDeviceIoControlFile, status:0

x0, event:0x514, iostatus:0x0, information:0x10, code:0x1202F, inlen:0x0, outlen


:0x10, handle:0x55C, path:"\Device\Afd\Endpoint"
pid:4092, tid:1488, tick:0x33D702E, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x50C, iostatus:0x0, information:0x0, code:0x12047, inlen:0xA4, outlen
:0x0, handle:0x53C, path:"\Device\Afd\Endpoint"
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x514, iostatus:0x0, information:0x0, code:0x120BF, inlen:0x18, outlen
:0x0, handle:0x55C, path:"\Device\Afd\Endpoint"
pid:4092, tid:1488, tick:0x33D702E, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x50C, iostatus:0x0, information:0x0, code:0x120BF, inlen:0x18, outlen
:0x0, handle:0x53C, path:"\Device\Afd\Endpoint"
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x514, iostatus:0x0, information:0x0, code:0x12047, inlen:0xA4, outlen
:0x0, handle:0x55C, path:"\Device\Afd\Endpoint"
pid:4092, tid:1488, tick:0x33D702E, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x50C, iostatus:0x0, information:0x0, code:0x120BF, inlen:0x18, outlen
:0x0, handle:0x53C, path:"\Device\Afd\Endpoint"
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x514, iostatus:0x0, information:0x0, code:0x120BF, inlen:0x18, outlen
:0x0, handle:0x55C, path:"\Device\Afd\Endpoint"
pid:4092, tid:1488, tick:0x33D702E, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x50C, iostatus:0x0, information:0x0, code:0x1203B, inlen:0x10, outlen
:0x0, handle:0x53C, path:"\Device\Afd\Endpoint"
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x514, iostatus:0x0, information:0x0, code:0x120BF, inlen:0x18, outlen
:0x0, handle:0x55C, path:"\Device\Afd\Endpoint"
pid:4092, tid:1488, tick:0x33D702E, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x50C, iostatus:0x0, information:0x0, code:0x12047, inlen:0xA4, outlen
:0x0, handle:0x53C, path:"\Device\Afd\Endpoint"
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x514, iostatus:0x0, information:0x0, code:0x1203B, inlen:0x10, outlen
:0x0, handle:0x55C, path:"\Device\Afd\Endpoint"
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x514, iostatus:0x0, information:0x0, code:0x12047, inlen:0xA4, outlen
:0x0, handle:0x55C, path:"\Device\Afd\Endpoint"
pid:4092, tid:1488, tick:0x33D702E, lvl:OK, func:NtDeviceIoControlFile, status:0
x103, iostatus:0x103, information:0x0, code:0x120C7, inlen:0x1A, outlen:0x0, han
dle:0x53C, path:"\Device\Afd\Endpoint"
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtDeviceIoControlFile, status:0
x103, iostatus:0x103, information:0x0, code:0x120C7, inlen:0x1A, outlen:0x0, han
dle:0x55C, path:"\Device\Afd\Endpoint"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x92, handle:0x422, path:"\Registry\User\S-1-5-21
-2360094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x422, path:"\Registry\User\S-1-5-21-23
60094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\Registry\User\S-1-5-21-2360094602-260238339
7-2463990887-1001_Classes\AppID\firefox.exe"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\Registry\Machine\Software\Classes\AppID\fir
efox.exe"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x92, handle:0x422, path:"\Registry\User\S-1-5-21
-2360094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20119, path:"\Registry\User\S-1-5-21-2360094602-260238339
7-2463990887-1001_Classes\AppID\firefox.exe"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034

, handle:0x0, access:0x20119, path:"\Registry\Machine\Software\Classes\AppID\fir


efox.exe"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x590, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\OLE\AppCompat
"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"RaiseDefaultAuthnLevel", class:0x2, length:0x90, resultlength:0x0, h
andle:0x590, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\OLE\AppCompat"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
90
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x590, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\Microsoft\OLE"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DefaultAccessPermission", class:0x2, length:0x90, resultlength:0x0,
handle:0x590, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\OLE"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:New_NtQueryInformationToken::<
lambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0xC0000023, token:
0x594, class:0x19, length:0x0, returnlength:0x14
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x594, c
lass:0x19, length:0x14, returnlength:0x14, sid:"S-1-16-8192", attributes:0x60
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
94
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x74DC0000
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
90
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FC, class:0x1, length:0x4C, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x74DC0000
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
60
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
60
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryAttributesFile, status:
0xC0000034, path:"C:\WINDOWS\system32\rpcss.dll"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:LdrGetDllHandle, status:0xC000
0135, name:"C:\WINDOWS\system32\rpcss.dll"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenEvent, status:0xC0000034
, handle:0x0, access:0x100000, path:"\Sessions\1\BaseNamedObjects\MSFT.VSA.COM.D
ISABLE.4092"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenEvent, status:0xC0000034
, handle:0x0, access:0x100002, path:"\Sessions\1\BaseNamedObjects\MSFT.VSA.IEC.S
TATUS.6c736db0"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x92, handle:0x422, path:"\Registry\User\S-1-5-21
-2360094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x422, path:"\Registry\User\S-1-5-21-23
60094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034

, handle:0x0, access:0x20019, path:"\Registry\User\S-1-5-21-2360094602-260238339


7-2463990887-1001_Classes\Interface\{00000134-0000-0000-C000-000000000046}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5A0000, zerobits:0x0, commitsize:0x0, offset:0x220000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x3760000
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x3760000, zerobits:0x0, commitsize:0x0, offset:0x270000, viewsize:0x10
000, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5A0000
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x588, access:0x20019, path:"\Registry\Machine\Software\Classes\Interface\{0000
0134-0000-0000-C000-000000000046}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0xC2, handle:0x58A, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\Interface\{00000134-0000-0000-C000-000000000046}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x58A, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\Interface\{00000134-0000-0000-C000-000000000046}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001_Classes\WOW6432Node\Interface\{00000134-0000-0000-C000-0000000
00046}\ProxyStubClsid32"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x598, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\Int
erface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0xE4, handle:0x59A, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxySt
ubClsid32"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x59A, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubC
lsid32"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\WOW6432Node\Interface\{00000134-0000-0000-C000-00000
0000046}\ProxyStubClsid32"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"", class:0x2, length:0x90, resultlength:0x5A, handle:0x59A, path:"\REGISTRY\
MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{00000134-0000-0000-C000-00000000
0046}\ProxyStubClsid32"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
9A
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
8A
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQuerySecurityObject, status:

0xC0000023, class:0x17, length:0x0, requiredlength:0xE8, handle:0x588, path:"\RP


C Control"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQuerySecurityObject, status:0
x0, class:0x17, length:0xE8, requiredlength:0xE8, handle:0x588, path:"\RPC Contr
ol"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x598, c
lass:0xA, length:0x38, returnlength:0x38
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x598, c
lass:0x4, length:0x48, returnlength:0x20
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x598, c
lass:0x19, length:0x4C, returnlength:0x14, sid:"S-1-16-8192", attributes:0x60
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:New_NtQueryInformationToken::<
lambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0xC0000023, token:
0x598, class:0x5, length:0x0, returnlength:0x20
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x598, c
lass:0x5, length:0x20, returnlength:0x20
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:New_NtQueryInformationToken::<
lambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0xC0000023, token:
0x598, class:0x6, length:0x0, returnlength:0x60
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x598, c
lass:0x6, length:0x60, returnlength:0x60
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FC, class:0x29, length:0x48, returnlength:0x4
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x598, c
lass:0x29, length:0x48, returnlength:0x4
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x598, c
lass:0xA, length:0x38, returnlength:0x38
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x598, c
lass:0x4, length:0x48, returnlength:0x20
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x598, c
lass:0x19, length:0x4C, returnlength:0x14, sid:"S-1-16-8192", attributes:0x60
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:New_NtQueryInformationToken::<
lambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0xC0000023, token:
0x598, class:0x5, length:0x0, returnlength:0x20
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x598, c
lass:0x5, length:0x20, returnlength:0x20
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:New_NtQueryInformationToken::<
lambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0xC0000023, token:
0x598, class:0x6, length:0x0, returnlength:0x60
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x598, c
lass:0x6, length:0x60, returnlength:0x60
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FC, class:0x29, length:0x48, returnlength:0x4
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x598, c
lass:0x29, length:0x48, returnlength:0x4
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5

88
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
98
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQuerySecurityObject, status:
0xC0000023, class:0x17, length:0x0, requiredlength:0xE8, handle:0x598, path:"\RP
C Control"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQuerySecurityObject, status:0
x0, class:0x17, length:0xE8, requiredlength:0xE8, handle:0x598, path:"\RPC Contr
ol"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x588, c
lass:0xA, length:0x38, returnlength:0x38
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x588, c
lass:0x4, length:0x48, returnlength:0x20
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x588, c
lass:0x19, length:0x4C, returnlength:0x14, sid:"S-1-16-8192", attributes:0x60
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:New_NtQueryInformationToken::<
lambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0xC0000023, token:
0x588, class:0x5, length:0x0, returnlength:0x20
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x588, c
lass:0x5, length:0x20, returnlength:0x20
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:New_NtQueryInformationToken::<
lambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0xC0000023, token:
0x588, class:0x6, length:0x0, returnlength:0x60
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x588, c
lass:0x6, length:0x60, returnlength:0x60
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FC, class:0x29, length:0x48, returnlength:0x4
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x588, c
lass:0x29, length:0x48, returnlength:0x4
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x588, c
lass:0xA, length:0x38, returnlength:0x38
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x588, c
lass:0x4, length:0x48, returnlength:0x20
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x588, c
lass:0x19, length:0x4C, returnlength:0x14, sid:"S-1-16-8192", attributes:0x60
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:New_NtQueryInformationToken::<
lambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0xC0000023, token:
0x588, class:0x5, length:0x0, returnlength:0x20
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x588, c
lass:0x5, length:0x20, returnlength:0x20
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:New_NtQueryInformationToken::<
lambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0xC0000023, token:
0x588, class:0x6, length:0x0, returnlength:0x60
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x588, c
lass:0x6, length:0x60, returnlength:0x60

pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l


ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FC, class:0x29, length:0x48, returnlength:0x4
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x588, c
lass:0x29, length:0x48, returnlength:0x4
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
98
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
88
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQuerySecurityObject, status:
0xC0000023, class:0x17, length:0x0, requiredlength:0xE8, handle:0x588, path:"\RP
C Control"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQuerySecurityObject, status:0
x0, class:0x17, length:0xE8, requiredlength:0xE8, handle:0x588, path:"\RPC Contr
ol"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x598, c
lass:0xA, length:0x38, returnlength:0x38
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x598, c
lass:0x4, length:0x48, returnlength:0x20
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x598, c
lass:0x19, length:0x4C, returnlength:0x14, sid:"S-1-16-8192", attributes:0x60
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:New_NtQueryInformationToken::<
lambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0xC0000023, token:
0x598, class:0x5, length:0x0, returnlength:0x20
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x598, c
lass:0x5, length:0x20, returnlength:0x20
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:New_NtQueryInformationToken::<
lambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0xC0000023, token:
0x598, class:0x6, length:0x0, returnlength:0x60
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x598, c
lass:0x6, length:0x60, returnlength:0x60
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FC, class:0x29, length:0x48, returnlength:0x4
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x598, c
lass:0x29, length:0x48, returnlength:0x4
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x598, c
lass:0xA, length:0x38, returnlength:0x38
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x598, c
lass:0x4, length:0x48, returnlength:0x20
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x598, c
lass:0x19, length:0x4C, returnlength:0x14, sid:"S-1-16-8192", attributes:0x60
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:New_NtQueryInformationToken::<
lambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0xC0000023, token:
0x598, class:0x5, length:0x0, returnlength:0x20
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x598, c

lass:0x5, length:0x20, returnlength:0x20


pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:New_NtQueryInformationToken::<
lambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0xC0000023, token:
0x598, class:0x6, length:0x0, returnlength:0x60
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x598, c
lass:0x6, length:0x60, returnlength:0x60
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FC, class:0x29, length:0x48, returnlength:0x4
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x598, c
lass:0x29, length:0x48, returnlength:0x4
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
88
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
98
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQuerySecurityObject, status:
0xC0000023, class:0x17, length:0x0, requiredlength:0xE8, handle:0x598, path:"\RP
C Control"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQuerySecurityObject, status:0
x0, class:0x17, length:0xE8, requiredlength:0xE8, handle:0x598, path:"\RPC Contr
ol"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x588, c
lass:0xA, length:0x38, returnlength:0x38
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x588, c
lass:0x4, length:0x48, returnlength:0x20
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x588, c
lass:0x19, length:0x4C, returnlength:0x14, sid:"S-1-16-8192", attributes:0x60
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:New_NtQueryInformationToken::<
lambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0xC0000023, token:
0x588, class:0x5, length:0x0, returnlength:0x20
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x588, c
lass:0x5, length:0x20, returnlength:0x20
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:New_NtQueryInformationToken::<
lambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0xC0000023, token:
0x588, class:0x6, length:0x0, returnlength:0x60
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x588, c
lass:0x6, length:0x60, returnlength:0x60
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FC, class:0x29, length:0x48, returnlength:0x4
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x588, c
lass:0x29, length:0x48, returnlength:0x4
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x588, c
lass:0xA, length:0x38, returnlength:0x38
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x588, c
lass:0x4, length:0x48, returnlength:0x20
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l

ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x588, c


lass:0x19, length:0x4C, returnlength:0x14, sid:"S-1-16-8192", attributes:0x60
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:New_NtQueryInformationToken::<
lambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0xC0000023, token:
0x588, class:0x5, length:0x0, returnlength:0x20
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x588, c
lass:0x5, length:0x20, returnlength:0x20
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:New_NtQueryInformationToken::<
lambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0xC0000023, token:
0x588, class:0x6, length:0x0, returnlength:0x60
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x588, c
lass:0x6, length:0x60, returnlength:0x60
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FC, class:0x29, length:0x48, returnlength:0x4
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x588, c
lass:0x29, length:0x48, returnlength:0x4
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
98
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
88
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FC, class:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"combase.dll", module:0x74DC0000
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
9C
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x76B00000
pid:4092, tid:13216, tick:0x33D702E, lvl:LOG, func:BaseThreadInitThunk, log:"New
thread started (via BaseThreadInitThunk) at address: 0x74E7D370, parameter: 0x7
E4530"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x59C, access:0x1, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVe
rsion\PropertySystem\SystemPropertyHandlers"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:".exe", class:0x2, length:0x90, resultlength:0x19E6B4, handle:0x59C,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Pr
opertySystem\SystemPropertyHandlers"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
9C
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x59C, access:0x1, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVe
rsion\PropertySystem\PropertyHandlers\.exe"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"", class:0x2, length:0x90, resultlength:0x5A, handle:0x59C, path:"\REGISTRY\
MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\PropertySystem\Pro
pertyHandlers\.exe"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
9C
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x92, handle:0x386, path:"\REGISTRY\USER\S-1-5-21
-2360094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x386, path:"\REGISTRY\USER\S-1-5-21-23
60094602-2602383397-2463990887-1001_Classes"

pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034


, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001_Classes\CLSID\{66742402-F9B9-11D1-A202-0000F81FEDEE}\OverrideF
ileSystemProperties"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\Registry\Machine\Software\Classes\CLSID\{66
742402-F9B9-11D1-A202-0000F81FEDEE}\OverrideFileSystemProperties"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x92, handle:0x386, path:"\REGISTRY\USER\S-1-5-21
-2360094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x386, path:"\REGISTRY\USER\S-1-5-21-23
60094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001_Classes\CLSID\{66742402-F9B9-11D1-A202-0000F81FEDEE}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x59C, access:0x20019, path:"\Registry\Machine\Software\Classes\CLSID\{66742402
-F9B9-11D1-A202-0000F81FEDEE}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0xBA, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{66742402-F9B9-11D1-A202-0000F81FEDEE}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{66742402-F9B9-11D1-A202-0000F81FEDEE}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\WOW6432Node\CLSID\{66742402-F9B9-11D1-A202-0000F81FE
DEE}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"DisableProcessIsolation", class:0x2, length:0x90, resultlength:0x10, handle:
0x59E, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{66742402-F9B9
-11D1-A202-0000F81FEDEE}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0xBA, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{66742402-F9B9-11D1-A202-0000F81FEDEE}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{66742402-F9B9-11D1-A202-0000F81FEDEE}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\WOW6432Node\CLSID\{66742402-F9B9-11D1-A202-0000F81FE
DEE}"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"NoOplock", class:0x2, length:0x90, resultlength:0x10, handle:0x59E,
path:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{66742402-F9B9-11D1-A
202-0000F81FEDEE}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x92, handle:0x386, path:"\REGISTRY\USER\S-1-5-21
-2360094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x386, path:"\REGISTRY\USER\S-1-5-21-23

60094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001_Classes\ExplorerCLSIDFlags\{66742402-F9B9-11D1-A202-0000F81FED
EE}"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\Registry\Machine\Software\Classes\ExplorerC
LSIDFlags\{66742402-F9B9-11D1-A202-0000F81FEDEE}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0xBA, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{66742402-F9B9-11D1-A202-0000F81FEDEE}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{66742402-F9B9-11D1-A202-0000F81FEDEE}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\WOW6432Node\CLSID\{66742402-F9B9-11D1-A202-0000F81FE
DEE}"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"UseInProcHandlerCache", class:0x2, length:0x90, resultlength:0x80000
000, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{6
6742402-F9B9-11D1-A202-0000F81FEDEE}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0xBA, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{66742402-F9B9-11D1-A202-0000F81FEDEE}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{66742402-F9B9-11D1-A202-0000F81FEDEE}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\WOW6432Node\CLSID\{66742402-F9B9-11D1-A202-0000F81FE
DEE}"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"UseOutOfProcHandlerCache", class:0x2, length:0x90, resultlength:0x80
000000, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID
\{66742402-F9B9-11D1-A202-0000F81FEDEE}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
9E
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x59C, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{76765B11-3
F95-4AF2-AC9D-EA55D8994F1A}"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"AppID", class:0x2, length:0x400, resultlength:0x66742402, handle:0x5
9C, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{76765B11-3F95-4A
F2-AC9D-EA55D8994F1A}"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKey, status:0xC0000034,
handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node
\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}\LocalServer32"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
9C
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x92, handle:0x3C2, path:"\Registry\User\S-1-5-21

-2360094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x3C2, path:"\Registry\User\S-1-5-21-23
60094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\Registry\User\S-1-5-21-2360094602-260238339
7-2463990887-1001_Classes\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x59C, access:0x20019, path:"\Registry\Machine\Software\Classes\CLSID\{76765B11
-3F95-4AF2-AC9D-EA55D8994F1A}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0xBA, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_Classes\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}\T
reatAs"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\C
LSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}\TreatAs"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x204, resultlength:0xBA, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0xBA, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994
F1A}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"", class:0x2, length:0x90, resultlength:0x52, handle:0x59E, path:"\REGISTRY\
MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A
}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0xBA, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383

397-2463990887-1001_Classes\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994
F1A}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"", class:0x2, length:0x90, resultlength:0x52, handle:0x59E, path:"\REGISTRY\
MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A
}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0xBA, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001_Classes\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1
A}\InprocServer32"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x5A0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLS
ID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}\InprocServer32"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0xD8, handle:0x5A2, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}\InProcServe
r32"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x5A2, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}\InProcServer32
"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994
F1A}\InProcServer32"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"InprocServer32", class:0x2, length:0x90, resultlength:0x0, handle:0x
5A2, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{76765B11-3F95-4
AF2-AC9D-EA55D8994F1A}\InProcServer32"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0xD8, handle:0x5A2, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}\InProcServe
r32"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x5A2, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}\InProcServer32
"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994
F1A}\InProcServer32"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryValueKey, status:0x0, na

me:"", class:0x2, length:0x90, resultlength:0x50, handle:0x5A2, path:"\REGISTRY\


MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A
}\InProcServer32"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0xD8, handle:0x5A2, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}\InProcServe
r32"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x5A2, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}\InProcServer32
"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994
F1A}\InProcServer32"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"", class:0x2, length:0x90, resultlength:0x50, handle:0x5A2, path:"\REGISTRY\
MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A
}\InProcServer32"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0xD8, handle:0x5A2, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}\InProcServe
r32"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x5A2, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}\InProcServer32
"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994
F1A}\InProcServer32"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"", class:0x2, length:0x90, resultlength:0x50, handle:0x5A2, path:"\REGISTRY\
MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A
}\InProcServer32"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0xD8, handle:0x5A2, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}\InProcServe
r32"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x5A2, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}\InProcServer32
"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994
F1A}\InProcServer32"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryValueKey, status:0x0, na

me:"ThreadingModel", class:0x2, length:0x90, resultlength:0x16, handle:0x5A2, pa


th:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9
D-EA55D8994F1A}\InProcServer32"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
A2
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0xBA, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_Classes\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}\I
nprocHandler32"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\C
LSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}\InprocHandler32"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0xBA, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_Classes\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}\I
nprocHandler"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\C
LSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}\InprocHandler"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
9E
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x92, handle:0x422, path:"\Registry\User\S-1-5-21
-2360094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x422, path:"\Registry\User\S-1-5-21-23
60094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\Registry\User\S-1-5-21-2360094602-260238339
7-2463990887-1001_Classes\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x59C, access:0x20019, path:"\Registry\Machine\Software\Classes\CLSID\{76765B11
-3F95-4AF2-AC9D-EA55D8994F1A}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0xBA, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l

ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF


FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001_Classes\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1
A}\TreatAs"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432No
de\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}\TreatAs"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
9E
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:CoCreateInstance, hr:0x0, clsid
:76765B11-3F95-4AF2-AC9D-EA55D8994F1A, context:0x1, riid:00000000-0000-0000-C000
-000000000046
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x76B00000
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\Software\Policies\Microsoft\Wi
ndows\Explorer"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\Software\Policies\Microsoft\Windows\Explorer"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x92, handle:0x386, path:"\REGISTRY\USER\S-1-5-21
-2360094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x386, path:"\REGISTRY\USER\S-1-5-21-23
60094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001_Classes\CLSID\{F324E4F9-8496-40B2-A1FF-9617C1C9AFFE}\Instance"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\Registry\Machine\Software\Classes\CLSID\{F3
24E4F9-8496-40B2-A1FF-9617C1C9AFFE}\Instance"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"shell32.dll", handle:0x75670000
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x75670000, name:"DllGetClassObject", ordinal:0x0, address:
0x757FDCA0, image:0x0, caller:0x76CCD1BF
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0x58, handle:0x576, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\exefile"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x576, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\exefile"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\exefile"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"AppUserModelID", class:0x2, length:0x90, resultlength:0x20, handle:0
x576, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\exefile"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x58, handle:0x576, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\exefile"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0

x7, length:0x4, resultlength:0x4, handle:0x576, path:"\REGISTRY\MACHINE\SOFTWARE


\Classes\exefile"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_Classes\exefile\Application"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\exefile\Appli
cation"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x6E, handle:0x53A, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\exefile\shell\open"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x53A, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\exefile\shell\open"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_Classes\exefile\shell\open\command"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x59C, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\exefile\shell\open\
command"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0x7E, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\exefile\shell\open\command"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\exefile\shell\open\command"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\exefile\shell\open\command"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DelegateExecute", class:0x2, length:0x90, resultlength:0x19F3F8, han
dle:0x59E, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\exefile\shell\open\command"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
9E
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x6E, handle:0x53A, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\exefile\shell\open"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x53A, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\exefile\shell\open"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_Classes\exefile\shell\open\DropTarget"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034

, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\exefile\shell


\open\DropTarget"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x77BC0000
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x76B00000
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x77BC0000
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x59C, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{7B8A2D94-0
AC9-11D1-896C-00C04FB6BFC4}"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"AppID", class:0x2, length:0x400, resultlength:0x63002D, handle:0x59C
, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{7B8A2D94-0AC9-11D1
-896C-00C04FB6BFC4}"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKey, status:0xC0000034,
handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node
\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}\LocalServer32"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
9C
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x92, handle:0x3C2, path:"\Registry\User\S-1-5-21
-2360094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x3C2, path:"\Registry\User\S-1-5-21-23
60094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\Registry\User\S-1-5-21-2360094602-260238339
7-2463990887-1001_Classes\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x59C, access:0x20019, path:"\Registry\Machine\Software\Classes\CLSID\{7B8A2D94
-0AC9-11D1-896C-00C04FB6BFC4}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0xBA, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_Classes\WOW6432Node\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}\T
reatAs"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\C
LSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}\TreatAs"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x204, resultlength:0xBA, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0xBA, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF

FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833


97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\WOW6432Node\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6B
FC4}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"", class:0x2, length:0x90, resultlength:0x2E, handle:0x59E, path:"\REGISTRY\
MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4
}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0xBA, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\WOW6432Node\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6B
FC4}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"", class:0x2, length:0x90, resultlength:0x2E, handle:0x59E, path:"\REGISTRY\
MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4
}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0xBA, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001_Classes\WOW6432Node\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC
4}\InprocServer32"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x5A0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLS
ID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}\InprocServer32"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0xD8, handle:0x5A2, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}\InprocServe
r32"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x5A2, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}\InprocServer32
"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\WOW6432Node\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6B

FC4}\InprocServer32"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"InprocServer32", class:0x2, length:0x90, resultlength:0x0, handle:0x
5A2, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{7B8A2D94-0AC9-1
1D1-896C-00C04FB6BFC4}\InprocServer32"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0xD8, handle:0x5A2, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}\InprocServe
r32"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x5A2, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}\InprocServer32
"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\WOW6432Node\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6B
FC4}\InprocServer32"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"", class:0x2, length:0x90, resultlength:0x4A, handle:0x5A2, path:"\REGISTRY\
MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4
}\InprocServer32"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0xD8, handle:0x5A2, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}\InprocServe
r32"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x5A2, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}\InprocServer32
"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\WOW6432Node\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6B
FC4}\InprocServer32"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"", class:0x2, length:0x90, resultlength:0x4A, handle:0x5A2, path:"\REGISTRY\
MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4
}\InprocServer32"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0xD8, handle:0x5A2, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}\InprocServe
r32"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x5A2, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}\InprocServer32
"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\WOW6432Node\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6B

FC4}\InprocServer32"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ThreadingModel", class:0x2, length:0x90, resultlength:0x16, handle:0x5A2, pa
th:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{7B8A2D94-0AC9-11D1-896
C-00C04FB6BFC4}\InprocServer32"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
A2
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0xBA, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_Classes\WOW6432Node\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}\I
nprocHandler32"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\C
LSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}\InprocHandler32"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0xBA, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_Classes\WOW6432Node\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}\I
nprocHandler"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\C
LSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}\InprocHandler"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
9E
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x92, handle:0x422, path:"\Registry\User\S-1-5-21
-2360094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x422, path:"\Registry\User\S-1-5-21-23
60094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\Registry\User\S-1-5-21-2360094602-260238339
7-2463990887-1001_Classes\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x59C, access:0x20019, path:"\Registry\Machine\Software\Classes\CLSID\{7B8A2D94
-0AC9-11D1-896C-00C04FB6BFC4}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0xBA, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTWARE

\Classes\WOW6432Node\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001_Classes\WOW6432Node\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC
4}\TreatAs"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432No
de\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}\TreatAs"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
9E
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"C:\Windows\SysWOW64\urlmon.dll", handle:0x73500000
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x73500000, name:"DllGetClassObject", ordinal:0x0, address:
0x73578D60, image:0x0, caller:0x74E6C7CB
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:LdrGetProcedureAddressForCalle
r, status:0xC0000139, module:0x73500000, name:"DllGetActivationFactory", ordinal
:0x0, image:0x0, caller:0x74E6C7DD
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x73500000, name:"DllCanUnloadNow", ordinal:0x0, address:0x
73579820, image:0x0, caller:0x74E6C841
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:CoCreateInstance, hr:0x0, clsid
:7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4, context:0x1, riid:79EAC9EE-BAF9-11CE-8C82
-00AA004BA90B
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_I
NITIALIZE_URLACTION_SHELLEXECUTE_TO_ALLOW_KB936610"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft
\Internet Explorer\Main\FeatureControl\FEATURE_INITIALIZE_URLACTION_SHELLEXECUTE
_TO_ALLOW_KB936610"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x59C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Internet Explorer\Security"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DisableSecuritySettingsCheck", class:0x2, length:0x90, resultlength:
0x0, handle:0x59C, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246399088
7-1001\SOFTWARE\Microsoft\Internet Explorer\Security"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
9C
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x59C, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Internet Expl
orer\Security"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DisableSecuritySettingsCheck", class:0x2, length:0x90, resultlength:
0x0, handle:0x59C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Intern
et Explorer\Security"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
9C
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"API-MS-WIN-CORE-URL-L1-1-0.DLL", handle:0x776F0000
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x776F0000, name:"PathCreateFromUrlW", ordinal:0x0, address
:0x77797370, image:0x0, caller:0x72A3C190
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034

, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24


63990887-1001\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_Z
ONES_DEFAULT_DRIVE_INTRANET_KB941000"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft
\Internet Explorer\Main\FeatureControl\FEATURE_ZONES_DEFAULT_DRIVE_INTRANET_KB94
1000"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"SpecialFoldersCacheSize", class:0x2, length:0x90, resultlength:0xA8,
handle:0x3E4, path:"\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\Curre
ntVersion\Internet Settings"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"SpecialFoldersCacheSize", class:0x2, length:0x90, resultlength:0xA8,
handle:0x3A8, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-10
01\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"SpecialFoldersCacheSize", class:0x2, length:0x90, resultlength:0xA8,
handle:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-10
01\Software\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"SpecialFoldersCacheSize", class:0x2, length:0x90, resultlength:0xA8,
handle:0x3F4, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Cu
rrentVersion\Internet Settings"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"api-ms-win-shell-shellfolders-l1-1-0.dll", handle:0x76B00000
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x76B00000, name:"SHGetFolderPathW", ordinal:0x0, address:0
x76C87230, image:0x0, caller:0x735747A8
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtSetInformationProcess, status
:0x0, class:0xC, length:0x4
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x80, path:"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtOpenFile, status:0x0, handle:
0x5A4, access:0x100001, iostatus:0x0, information:0x1, share:0x7, options:0x4021
, path:"C:\Program Files (x86)\Mozilla Firefox\"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryDirectoryFile, status:0x
0, iostatus:0x0, information:0x78, length:0x268, class:0x3, single:0x1, mask:"fi
refox.exe", restart:0x0, handle:0x5A4, path:"C:\Program Files (x86)\Mozilla Fire
fox"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
A4
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtSetInformationProcess, status
:0x0, class:0xC, length:0x4
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x80, path:"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x10, path:"C:\Program Files (x86)\Mozilla Firefox"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x11, path:"C:\Program Files (x86)"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtCreateFile, status:0x0, handl
e:0x59C, access:0x120080, iostatus:0x0, information:0x0, attribs:0x0, share:0x3,
disposition:0x1, options:0x60, path:"C:\Program Files (x86)\Mozilla Firefox\fir
efox.exe"
pid:4092, tid:2168, tick:0x33D703E, lvl:WRN, func:NtQuerySecurityObject, status:
0xC000000D, class:0x10, length:0x0, requiredlength:0x0, handle:0x59C, path:"C:\P
rogram Files (x86)\Mozilla Firefox\firefox.exe"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtClose, status:0x0, handle:0x5
9C
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"api-ms-win-shlwapi-ie-l1-1-0.dll", handle:0x77BC0000

pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:LdrGetProcedureAddressForCaller


, status:0x0, module:0x77BC0000, name:"PathFileExistsAndAttributesW", ordinal:0x
0, address:0x77BD5F40, image:0x0, caller:0x735747A8
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtSetInformationProcess, status
:0x0, class:0xC, length:0x4
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x80, path:"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtSetInformationProcess, status
:0x0, class:0xC, length:0x4
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtSetInformationProcess, status
:0x0, class:0xC, length:0x4
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x80, path:"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtSetInformationProcess, status
:0x0, class:0xC, length:0x4
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtSetInformationProcess, status
:0x0, class:0xC, length:0x4
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:NtQueryAttributesFile, status:
0xC0000034, path:"C:\Program Files (x86)\Mozilla Firefox\firefox.exe:Zone.Identi
fier"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtSetInformationProcess, status
:0x0, class:0xC, length:0x4
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_P
ROTOCOL_LOCKDOWN"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x59C, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Inter
net Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN"
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"firefox.exe", class:0x2, length:0x90, resultlength:0xAA1199, handle:
0x59C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\
Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN"
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"*", class:0x2, length:0x90, resultlength:0xAA1199, handle:0x59C, pat
h:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\Featu
reControl\FEATURE_PROTOCOL_LOCKDOWN"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtClose, status:0x0, handle:0x5
9C
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x59C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0"
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"1806", class:0x2, length:0x90, resultlength:0xA90BB7, handle:0x59C,
path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Mic
rosoft\Windows\CurrentVersion\Internet Settings\Zones\0"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x5A0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\Curre
ntVersion\Internet Settings\Zones\0"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"1806", class:0x2, length:0x90, resultlength:0x10, handle:0x5A0, path:"\REGIS
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Internet Setti
ngs\Zones\0"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtClose, status:0x0, handle:0x5
9C
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtClose, status:0x0, handle:0x5
A0
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x75670000
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtOpenKey, status:0x0, handle:0

x5A0, access:0x20019, path:"\Registry\Machine\Software\Policies\Microsoft\Window


s\Safer\CodeIdentifiers"
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"TransparentEnabled", class:0x1, length:0x20C, resultlength:0x0, hand
le:0x5A0, path:"\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\safer\code
identifiers"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtClose, status:0x0, handle:0x5
A0
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x6E, handle:0x53A, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\exefile\shell\open"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x53A, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\exefile\shell\open"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_Classes\exefile\shell\open\command"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x5A0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\exefile\shell\open\
command"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0x7E, handle:0x5A2, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\exefile\shell\open\command"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x5A2, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\exefile\shell\open\command"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\exefile\shell\open\command"
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"command", class:0x2, length:0x90, resultlength:0x0, handle:0x5A2, pa
th:"\REGISTRY\MACHINE\SOFTWARE\Classes\exefile\shell\open\command"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtClose, status:0x0, handle:0x5
A2
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x6E, handle:0x53A, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\exefile\shell\open"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x53A, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\exefile\shell\open"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_Classes\exefile\shell\open\command"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x5A0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\exefile\shell\open\
command"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0x7E, handle:0x5A2, path:"\REGISTRY\MACHINE\SOFTW

ARE\Classes\exefile\shell\open\command"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x5A2, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\exefile\shell\open\command"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\exefile\shell\open\command"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"", class:0x2, length:0x90, resultlength:0x1C, handle:0x5A2, path:"\REGISTRY\
MACHINE\SOFTWARE\Classes\exefile\shell\open\command"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtClose, status:0x0, handle:0x5
A2
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x5A0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{CDC82860-4
68D-4D4E-B7E7-C298FF23AB2C}"
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"AppID", class:0x2, length:0x400, resultlength:0x1D0000, handle:0x5A0
, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E
-B7E7-C298FF23AB2C}"
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:NtOpenKey, status:0xC0000034,
handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node
\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2C}\LocalServer32"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtClose, status:0x0, handle:0x5
A0
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x92, handle:0x3C2, path:"\Registry\User\S-1-5-21
-2360094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x3C2, path:"\Registry\User\S-1-5-21-23
60094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\Registry\User\S-1-5-21-2360094602-260238339
7-2463990887-1001_Classes\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2C}"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x5A0, access:0x20019, path:"\Registry\Machine\Software\Classes\CLSID\{CDC82860
-468D-4D4E-B7E7-C298FF23AB2C}"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0xBA, handle:0x5A2, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2C}"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x5A2, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2C}"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2C}\T
reatAs"
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\C
LSID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2C}\TreatAs"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x204, resultlength:0xBA, handle:0x5A2, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2C}"

pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0


x3, length:0x188, resultlength:0xBA, handle:0x5A2, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2C}"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x5A2, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2C}"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23A
B2C}"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"", class:0x2, length:0x90, resultlength:0x58, handle:0x5A2, path:"\REGISTRY\
MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2C
}"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0xBA, handle:0x5A2, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2C}"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x5A2, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2C}"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23A
B2C}"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"", class:0x2, length:0x90, resultlength:0x58, handle:0x5A2, path:"\REGISTRY\
MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2C
}"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0xBA, handle:0x5A2, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2C}"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x5A2, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2C}"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001_Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2
C}\InprocServer32"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x59C, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLS
ID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2C}\InprocServer32"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0xD8, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2C}\InProcServe
r32"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2C}\InProcServer32

"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23A
B2C}\InProcServer32"
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"InprocServer32", class:0x2, length:0x90, resultlength:0x0, handle:0x
59E, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{CDC82860-468D-4
D4E-B7E7-C298FF23AB2C}\InProcServer32"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0xD8, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2C}\InProcServe
r32"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2C}\InProcServer32
"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23A
B2C}\InProcServer32"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"", class:0x2, length:0x90, resultlength:0x60, handle:0x59E, path:"\REGISTRY\
MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2C
}\InProcServer32"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0xD8, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2C}\InProcServe
r32"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2C}\InProcServer32
"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23A
B2C}\InProcServer32"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"", class:0x2, length:0x90, resultlength:0x60, handle:0x59E, path:"\REGISTRY\
MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2C
}\InProcServer32"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0xD8, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2C}\InProcServe
r32"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2C}\InProcServer32

"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23A
B2C}\InProcServer32"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"", class:0x2, length:0x90, resultlength:0x60, handle:0x59E, path:"\REGISTRY\
MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2C
}\InProcServer32"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0xD8, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2C}\InProcServe
r32"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2C}\InProcServer32
"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23A
B2C}\InProcServer32"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ThreadingModel", class:0x2, length:0x90, resultlength:0x16, handle:0x59E, pa
th:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E
7-C298FF23AB2C}\InProcServer32"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtClose, status:0x0, handle:0x5
9E
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0xBA, handle:0x5A2, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2C}"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x5A2, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2C}"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2C}\I
nprocHandler32"
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\C
LSID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2C}\InprocHandler32"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0xBA, handle:0x5A2, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2C}"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x5A2, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2C}"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF

FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833


97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2C}\I
nprocHandler"
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\C
LSID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2C}\InprocHandler"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtClose, status:0x0, handle:0x5
A2
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x92, handle:0x422, path:"\Registry\User\S-1-5-21
-2360094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x422, path:"\Registry\User\S-1-5-21-23
60094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\Registry\User\S-1-5-21-2360094602-260238339
7-2463990887-1001_Classes\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2C}"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x5A0, access:0x20019, path:"\Registry\Machine\Software\Classes\CLSID\{CDC82860
-468D-4D4E-B7E7-C298FF23AB2C}"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0xBA, handle:0x5A2, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2C}"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x5A2, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2C}"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001_Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2
C}\TreatAs"
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432No
de\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2C}\TreatAs"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtClose, status:0x0, handle:0x5
A2
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"C:\WINDOWS\system32\windows.storage.dll", handle:0x76B00000
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x76B00000, name:"DllGetClassObject", ordinal:0x0, address:
0x76CCD4E0, image:0x0, caller:0x74E6C7CB
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x76B00000, name:"DllGetActivationFactory", ordinal:0x0, ad
dress:0x76CEDEA0, image:0x0, caller:0x74E6C7DD
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x76B00000, name:"DllCanUnloadNow", ordinal:0x0, address:0x
76CEAF80, image:0x0, caller:0x74E6C841
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:CoCreateInstance, hr:0x0, clsid
:CDC82860-468D-4D4E-B7E7-C298FF23AB2C, context:0x1, riid:5632B1A4-E38A-400A-928A
-D4CD63230295
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2E1D0F0, class:0x3, length:0x14
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2E1D0F0, class:0x3, length:0x14

pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryVirtualMemory, status:0x


0, address:0x2E1D0F0, class:0x3, length:0x14
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2E1D0F0, class:0x3, length:0x14
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2E1D0F0, class:0x3, length:0x14
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x92, handle:0x386, path:"\REGISTRY\USER\S-1-5-21
-2360094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x386, path:"\REGISTRY\USER\S-1-5-21-23
60094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001_Classes\.exe"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x5A0, access:0x20019, path:"\Registry\Machine\Software\Classes\.exe"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0x52, handle:0x5A2, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\.exe"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x5A2, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\.exe"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\.exe"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"", class:0x2, length:0x90, resultlength:0x1C, handle:0x5A2, path:"\REGISTRY\
MACHINE\SOFTWARE\Classes\.exe"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x92, handle:0x386, path:"\REGISTRY\USER\S-1-5-21
-2360094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x386, path:"\REGISTRY\USER\S-1-5-21-23
60094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001_Classes\exefile"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x59C, access:0x20019, path:"\Registry\Machine\Software\Classes\exefile"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x58, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\exefile"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\exefile"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_Classes\exefile\CurVer"
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\exefile\CurVe
r"

pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0


x3, length:0x180, resultlength:0x58, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\exefile"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\exefile"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001_Classes\exefile"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x5A4, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\exefile\"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtClose, status:0x0, handle:0x5
9E
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x58, handle:0x5A6, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\exefile"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x5A6, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\exefile"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_Classes\exefile\Progid"
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\exefile\Progi
d"
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\Cur
rentVersion\ShellCompatibility\ProgIDs\exefile"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtClose, status:0x0, handle:0x5
A2
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtClose, status:0x0, handle:0x5
A6
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x5A4, access:0x1, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVe
rsion\Policies\Explorer"
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"InheritConsoleHandles", class:0x2, length:0x90, resultlength:0x19F31
8, handle:0x5A4, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Windows\CurrentVersi
on\Policies\Explorer"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtClose, status:0x0, handle:0x5
A4
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x6E, handle:0x53A, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\exefile\shell\open"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x53A, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\exefile\shell\open"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF

FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833


97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_Classes\exefile\shell\open\ddeexec"
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\exefile\shell
\open\ddeexec"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x76B00000
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x5A4, access:0x1, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVe
rsion\Policies\Explorer"
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"RestrictRun", class:0x2, length:0x90, resultlength:0x19F330, handle:
0x5A4, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Windows\CurrentVersion\Policie
s\Explorer"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtClose, status:0x0, handle:0x5
A4
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x5A4, access:0x1, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVe
rsion\Policies\Explorer"
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DisallowRun", class:0x2, length:0x90, resultlength:0x19F330, handle:
0x5A4, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Windows\CurrentVersion\Policie
s\Explorer"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtClose, status:0x0, handle:0x5
A4
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001\Software\Microsoft\Windows\CurrentVersion\App Paths\firefox.ex
e"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5A0000, zerobits:0x0, commitsize:0x0, offset:0x220000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x3760000
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x5A4, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\Curre
ntVersion\App Paths\firefox.exe"
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"AppendPath", class:0x2, length:0x90, resultlength:0x0, handle:0x5A4,
path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\fir
efox.exe"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"PATH", class:0x2, length:0x90, resultlength:0x52, handle:0x5A4, path:"\REGIS
TRY\MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\firefox.exe"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtClose, status:0x0, handle:0x5
A4
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x76B00000
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0x6E, handle:0x53A, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\exefile\shell\open"

pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0


x7, length:0x4, resultlength:0x4, handle:0x53A, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\exefile\shell\open"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\exefile\shell\open"
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"SetWorkingDirectoryFromTarget", class:0x2, length:0x90, resultlength
:0x19F604, handle:0x53A, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\exefile\shell\
open"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0x6E, handle:0x53A, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\exefile\shell\open"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x53A, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\exefile\shell\open"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\exefile\shell\open"
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"NoWorkingDirectory", class:0x2, length:0x90, resultlength:0x19F604,
handle:0x53A, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\exefile\shell\open"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x5A4, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\
Volume"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x5A0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\
Volume\{3095dd51-a141-42a6-8c53-8590cc53fbc1}\"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtClose, status:0x0, handle:0x5
A4
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Generation", class:0x2, length:0x90, resultlength:0x10, handle:0x5A0, path:"
\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft
\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3095dd51-a141-42a6-8c5
3-8590cc53fbc1}"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtClose, status:0x0, handle:0x5
A0
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:UpdateProcThreadAttribute, ret:
0x1, gle:0x0, Attribute:0x60001
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:New_NtQueryInformationToken::<
lambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0xC0000023, token:
0xFFFFFFFC, class:0x27, length:0x0, returnlength:0x68
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FC, class:0x27, length:0x68, returnlength:0x68
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtCreateFile, status:0x0, handl
e:0x5A0, access:0x80100080, iostatus:0x0, information:0x0, attribs:0x80, share:0
x5, disposition:0x1, options:0x60, path:"C:\Program Files (x86)\Mozilla Firefox\
firefox.exe"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtCreateSection, status:0x0, ha

ndle:0x59C, access:0x1, pageattribs:0x2, sectionattribs:0x11000000, file:0x5A0


pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQuerySection, status:0x0, cla
ss:0x1, length:0x30, handle:0x59C, path:"C:\Program Files (x86)\Mozilla Firefox\
firefox.exe"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtClose, status:0x0, handle:0x5
9C
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x59C, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887
-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Cache", class:0x1, length:0x208, resultlength:0x98, handle:0x59C, path:"\REG
ISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Win
dows\CurrentVersion\Explorer\Shell Folders"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtClose, status:0x0, handle:0x5
9C
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x59C, access:0x8, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887
-1001\Software\Microsoft\Windows NT\CurrentVersion"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x5A4, access:0x101, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24639908
87-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers"
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"C:\Program Files (x86)\Mozilla Firefox\firefox.exe", class:0x2, leng
th:0x10, resultlength:0x0, handle:0x5A4, path:"\REGISTRY\USER\S-1-5-21-236009460
2-2602383397-2463990887-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCom
patFlags\Layers"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtClose, status:0x0, handle:0x5
A4
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x3760000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x10
000, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5A0000
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5A0000, zerobits:0x0, commitsize:0x0, offset:0x210000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x3760000
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x3760000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x10
000, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5A0000
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5A0000, zerobits:0x0, commitsize:0x0, offset:0x210000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x3760000
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x3760000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x10
000, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtUnmapViewOfSection, status:0x

0, address:0x5A0000
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5A0000, zerobits:0x0, commitsize:0x0, offset:0x210000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x3760000
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding directory _CrashReporter@1.0.0.0 with flags: 2."
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding directory _Firefox@1.0.0.0 with flags: 2."
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding directory _MaintenanceService@1.0.0.0 with flags: 2."
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding directory _Mozilla.WebAppRT@1.0.0.0 with flags: 2."
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding directory _Nullsoft.NSIS.exehead@1.0.0.0 with flags: 2."
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding directory _plugin-container@1.0.0.0 with flags: 2."
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding directory _plugin-hang-ui@1.0.0.0 with flags: 2."
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding directory _Updater@1.0.0.0 with flags: 2."
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding directory Manifests with flags: 2."
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding directory X86_7zS.sfx.exe@1.0.0.0 with flags: 2."
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x3760000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x10
000, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5A0000
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:RecurseDirectoryConfig, log:"D
uplicate directory Manifests will not be added as it is at lower layer."
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding directory x86_Adobe.FlashPlayer.Installer@14.0.0.125 with flags: 2."
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding directory x86_Adobe.FlashPlayer.Uninstaller@14.0.0.125 with flags: 2."
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding directory X86_Adobe.SAFlashPlayer@14.0.0.125 with flags: 2."
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5A0000, zerobits:0x0, commitsize:0x0, offset:0x210000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x3760000
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x3760000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x10
000, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5A0000
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5A0000, zerobits:0x0, commitsize:0x0, offset:0x210000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x3760000
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x3760000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x10
000, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5A0000
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtMapViewOfSection, status:0x0,

address:0x5A0000, zerobits:0x0, commitsize:0x0, offset:0x210000, viewsize:0x100


00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x3760000
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x3760000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x10
000, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5A0000
pid:4092, tid:2168, tick:0x33D704D, lvl:OK, func:NtOpenFile, status:0x0, handle:
0x5AC, access:0x1200A9, iostatus:0x0, information:0x1, share:0x5, options:0x60,
path:"C:\Users\i92segoa\AppData\Local\Temp\SPOON\CACHE\0xA527E666CB0D6807\sxs\ma
nifests\firefox.exe_0x9195B4884EA1918FD0ABEA589A684707.1.manifest"
pid:4092, tid:2168, tick:0x33D704D, lvl:OK, func:NtCreateSection, status:0x0, ha
ndle:0x5B0, access:0x4, pageattribs:0x2, sectionattribs:0x8000000, file:0x5AC
pid:4092, tid:2168, tick:0x33D704D, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5A0000, zerobits:0x0, commitsize:0x0, viewsize:0x1000, disposition:0x
1, type:0x0, protect:0x2, handle:0x5B0
pid:4092, tid:2168, tick:0x33D704D, lvl:LOG, func:NtOpenKey, status:0xC0000034,
handle:0x0, access:0x20019, path:"\Registry\MACHINE\Software\Microsoft\Windows\C
urrentVersion\SideBySide"
pid:4092, tid:2168, tick:0x33D704D, lvl:OK, func:NtQueryInformationFile, status:
0x0, iostatus:0x0, information:0x18, length:0x18, class:0x5, handle:0x5AC, path:
"C:\Users\i92segoa\AppData\Local\Temp\SPOON\CACHE\0xA527E666CB0D6807\sxs\Manifes
ts\firefox.exe_0x9195b4884ea1918fd0abea589a684707.1.manifest"
pid:4092, tid:2168, tick:0x33D704D, lvl:OK, func:NtQueryVolumeInformationFile, s
tatus:0x0, iostatus:0x0, information:0x8, length:0x8, class:0x4, handle:0x5AC, p
ath:"C:\Users\i92segoa\AppData\Local\Temp\SPOON\CACHE\0xA527E666CB0D6807\sxs\Man
ifests\firefox.exe_0x9195b4884ea1918fd0abea589a684707.1.manifest"
pid:4092, tid:2168, tick:0x33D704D, lvl:OK, func:NtQueryInformationFile, status:
0x0, iostatus:0x0, information:0x28, length:0x28, class:0x4, handle:0x5AC, path:
"C:\Users\i92segoa\AppData\Local\Temp\SPOON\CACHE\0xA527E666CB0D6807\sxs\Manifes
ts\firefox.exe_0x9195b4884ea1918fd0abea589a684707.1.manifest"
pid:4092, tid:2168, tick:0x33D704D, lvl:OK, func:NtClose, status:0x0, handle:0x5
AC
pid:4092, tid:2168, tick:0x33D704D, lvl:OK, func:NtClose, status:0x0, handle:0x5
B0
pid:4092, tid:2168, tick:0x33D704D, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5A0000
pid:4092, tid:2168, tick:0x33D704D, lvl:OK, func:CreateActCtxW, ret:0x804384, gl
e:0x0, flags:0x8, path:"C:\Program Files (x86)\Mozilla Firefox\firefox.exe", res
ourceid:0x1
pid:4092, tid:2168, tick:0x33D704D, lvl:OK, func:QueryActCtxW, ret:0x1, gle:0x0,
flags:0x80000000, actctx:0x804384, class:0x5, size:0xC, requiredsize:0xC
pid:4092, tid:2168, tick:0x33D704D, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x38D0000
pid:4092, tid:2168, tick:0x33D704D, lvl:OK, func:NtClose, status:0x0, handle:0x5
A0
pid:4092, tid:2168, tick:0x33D704D, lvl:OK, func:NtClose, status:0x0, handle:0x5
A0
pid:4092, tid:2168, tick:0x33D704D, lvl:OK, func:New_CheckTokenMembership::<lamb
da_02604bca4152832ac92161eb66d89101>::operator (), ret:0x1, gle:0x0, TokenHandle
:0x5B0, SidToCheck:"S-1-5-32-544", IsMember:0x0
pid:4092, tid:2168, tick:0x33D704D, lvl:OK, func:NtClose, status:0x0, handle:0x5
B0
pid:4092, tid:2168, tick:0x33D704D, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x5B0, c
lass:0x12, length:0x4, returnlength:0x4
pid:4092, tid:2168, tick:0x33D704D, lvl:OK, func:NtClose, status:0x0, handle:0x5
B0

pid:4092, tid:2168, tick:0x33D704D, lvl:OK, func:NtSetInformationProcess, status


:0x0, class:0xC, length:0x4
pid:4092, tid:2168, tick:0x33D704D, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x80, path:"c:\program files (x86)\mozilla firefox\firefox.exe"
pid:4092, tid:2168, tick:0x33D704D, lvl:OK, func:NtCreateFile, status:0x0, handl
e:0x5B0, access:0x80100080, iostatus:0x0, information:0x0, attribs:0x0, share:0x
5, disposition:0x1, options:0x60, path:"c:\program files (x86)\mozilla firefox\f
irefox.exe"
pid:4092, tid:2168, tick:0x33D704D, lvl:OK, func:NtCreateSection, status:0x0, ha
ndle:0x5AC, access:0x5, pageattribs:0x2, sectionattribs:0x11000000, file:0x5B0
pid:4092, tid:2168, tick:0x33D705D, lvl:OK, func:NtClose, status:0x0, handle:0x5
B8
pid:4092, tid:2168, tick:0x33D705D, lvl:OK, func:NtSetInformationProcess, status
:0x0, class:0x1, length:0x38
pid:4092, tid:2168, tick:0x33D705D, lvl:OK, func:NtClose, status:0x0, handle:0x5
BC
pid:4092, tid:2168, tick:0x33D705D, lvl:OK, func:NtMapViewOfSection, status:0x40
000003, address:0x38D0000, zerobits:0x0, commitsize:0x0, viewsize:0x63000, dispo
sition:0x1, type:0x800000, protect:0x2, handle:0x5AC, path:"C:\Program Files (x8
6)\Mozilla Firefox\firefox.exe"
pid:4092, tid:2168, tick:0x33D705D, lvl:OK, func:NtClose, status:0x0, handle:0x5
AC
pid:4092, tid:2168, tick:0x33D705D, lvl:OK, func:NtClose, status:0x0, handle:0x5
B0
pid:4092, tid:2168, tick:0x33D705D, lvl:OK, func:NtSetInformationProcess, status
:0x0, class:0xC, length:0x4
pid:4092, tid:2168, tick:0x33D705D, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x38D0000
pid:4092, tid:2168, tick:0x33D705D, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x10, path:"C:\Users\i92segoa\Desktop\Firefox SEO\"
pid:4092, tid:2168, tick:0x33D705D, lvl:OK, func:NtOpenFile, status:0x0, handle:
0x5A0, access:0x120089, iostatus:0x0, information:0x0, share:0x7, options:0x20,
path:"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
pid:4092, tid:2168, tick:0x33D705D, lvl:OK, func:NtCreateSection, status:0x0, ha
ndle:0x5BC, access:0x4, pageattribs:0x2, sectionattribs:0x8000000, file:0x5A0
pid:4092, tid:2168, tick:0x33D705D, lvl:OK, func:NtClose, status:0x0, handle:0x5
C0
pid:4092, tid:2168, tick:0x33D705D, lvl:OK, func:NtSetInformationProcess, status
:0x0, class:0x1, length:0x38
pid:4092, tid:2168, tick:0x33D705D, lvl:OK, func:NtClose, status:0x0, handle:0x5
C4
pid:4092, tid:2168, tick:0x33D705D, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x39D0000, zerobits:0x0, commitsize:0x0, viewsize:0x60000, disposition:
0x2, type:0x0, protect:0x2, handle:0x5BC, path:"C:\Program Files (x86)\Mozilla F
irefox\firefox.exe"
pid:4092, tid:2168, tick:0x33D705D, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x39D0000
pid:4092, tid:2168, tick:0x33D705D, lvl:OK, func:NtClose, status:0x0, handle:0x5
BC
pid:4092, tid:2168, tick:0x33D705D, lvl:OK, func:NtClose, status:0x0, handle:0x5
A0
pid:4092, tid:2168, tick:0x33D706D, lvl:LOG, func:_GetChildProcessCurrentDirecto
ry, log:"Got following current directory from proc: C:\Users\i92segoa\Desktop\Fi
refox SEO\"
pid:4092, tid:2168, tick:0x33D706D, lvl:OK, func:NtClose, status:0x0, handle:0x5
A4
pid:4092, tid:2168, tick:0x33D706D, lvl:OK, func:NtCreateUserProcess, status:0x0
, handle:0x5CC, processaccess:0x2000000, threadaccess:0x2000000, path:"\??\C:\Pr
ogram Files (x86)\Mozilla Firefox\firefox.exe"
pid:4092, tid:2168, tick:0x33D706D, lvl:LOG, func:NtOpenKey, status:0xC0000034,

handle:0x0, access:0x1, path:"\Registry\MACHINE\System\CurrentControlSet\Control


\Session Manager\AppCertDlls"
pid:4092, tid:2168, tick:0x33D706D, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x5A4, c
lass:0x1, length:0x88, returnlength:0x24, sid:"S-1-5-21-2360094602-2602383397-24
63990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D706D, lvl:LOG, func:NtOpenKey, status:0xC0000034,
handle:0x0, access:0x3, path:"\Registry\MACHINE\System\CurrentControlSet\Control
\SafeBoot\Option"
pid:4092, tid:2168, tick:0x33D706D, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x5D8, access:0x1, path:"\Registry\Machine\Software\Policies\Microsoft\Windows\Sa
fer\CodeIdentifiers"
pid:4092, tid:2168, tick:0x33D706D, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"TransparentEnabled", class:0x2, length:0x50, resultlength:0x77799049
, handle:0x5D8, path:"\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\safe
r\codeidentifiers"
pid:4092, tid:2168, tick:0x33D706D, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"AuthenticodeEnabled", class:0x2, length:0x50, resultlength:0x10, handle:0x5D
8, path:"\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentif
iers"
pid:4092, tid:2168, tick:0x33D706D, lvl:OK, func:NtClose, status:0x0, handle:0x5
D8
pid:4092, tid:2168, tick:0x33D706D, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D707C, lvl:LOG, func:NtOpenKey, status:0xC0000034,
handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"
pid:4092, tid:2168, tick:0x33D707C, lvl:OK, func:NtClose, status:0x0, handle:0x5
A4
pid:4092, tid:2168, tick:0x33D707C, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D707C, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x5D8, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887
-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders"
pid:4092, tid:2168, tick:0x33D707C, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Cache", class:0x1, length:0x208, resultlength:0x98, handle:0x5D8, path:"\REG
ISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Win
dows\CurrentVersion\Explorer\Shell Folders"
pid:4092, tid:2168, tick:0x33D707C, lvl:OK, func:NtClose, status:0x0, handle:0x5
D8
pid:4092, tid:2168, tick:0x33D707C, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x5D8, access:0x101, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24639908
87-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers"
pid:4092, tid:2168, tick:0x33D707C, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"C:\Program Files (x86)\Mozilla Firefox\firefox.exe", class:0x2, leng
th:0x10, resultlength:0x0, handle:0x5D8, path:"\REGISTRY\USER\S-1-5-21-236009460
2-2602383397-2463990887-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCom
patFlags\Layers"
pid:4092, tid:2168, tick:0x33D707C, lvl:OK, func:NtClose, status:0x0, handle:0x5
D8
pid:4092, tid:2168, tick:0x33D707C, lvl:LOG, func:NtOpenKey, status:0xC0000034,
handle:0x0, access:0x20019, path:"\Registry\MACHINE\Software\Microsoft\Windows\C
urrentVersion\SideBySide"
pid:4092, tid:2168, tick:0x33D707C, lvl:OK, func:NtClose, status:0x0, handle:0x5
D0
pid:4092, tid:2168, tick:0x33D707C, lvl:OK, func:NtClose, status:0x0, handle:0x5

D4
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:SetLastSeenChildProcThread, lo
g:"Setting last seen child proc thread to 0x5C8."
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtClose, status:0x0, handle:0x5
B0
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtClose, status:0x0, handle:0x5
AC
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:CreateProcessInternalW, ret:0x1
, gle:0x0, name:"C:\Program Files (x86)\Mozilla Firefox\firefox.exe", commandlin
e:"\"C:\Program Files (x86)\Mozilla Firefox\firefox.exe\" ", inherit:0x0, flags:
0x4080404, currentdir:"C:\Users\i92segoa\Desktop\Firefox SEO\"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x92, handle:0x386, path:"\REGISTRY\USER\S-1-5-21
-2360094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x386, path:"\REGISTRY\USER\S-1-5-21-23
60094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001_Classes\Applications\firefox.exe"
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\Registry\Machine\Software\Classes\Applicati
ons\firefox.exe"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x76B00000
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtOpenSection, status:0xC00000
34, handle:0x0, access:0xF, path:"\KnownDlls32\pcacli.dll"
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtQueryAttributesFile, status:
0xC0000034, path:"C:\Users\i92segoa\Desktop\Firefox SEO\pcacli.dll"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x20, path:"C:\WINDOWS\SYSTEM32\pcacli.dll"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtOpenFile, status:0x0, handle:
0x5AC, access:0x100021, iostatus:0x0, information:0x1, share:0x5, options:0x60,
path:"C:\WINDOWS\SYSTEM32\pcacli.dll"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtCreateSection, status:0x0, ha
ndle:0x5B0, access:0xF, pageattribs:0x10, sectionattribs:0x1000000, file:0x5AC
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x60AE0000, zerobits:0x0, commitsize:0x0, viewsize:0xC000, disposition:
0x1, type:0x800000, protect:0x4, handle:0x5B0, path:"C:\WINDOWS\SYSTEM32\pcacli.
dll"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtClose, status:0x0, handle:0x5
B0
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtClose, status:0x0, handle:0x5
AC
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x5B0, access:0x1, path:"\Registry\Machine\Software\Microsoft\Windows NT\CurrentV
ersion\AppCompatFlags"
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"LogFlags", class:0x2, length:0x14, resultlength:0x0, handle:0x5B0, p
ath:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\
AppCompatFlags"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtClose, status:0x0, handle:0x5
B0
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x20, path:"C:\WINDOWS\SYSTEM32\kernelbase.dll"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"api-ms-win-eventing-provider-l1-1-0", module:0x776F0000
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x776F0000, name:"EventSetInformation", ordinal:0x0, addres
s:0x77C39FC0, image:0x0, caller:0x60AE409A

pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:LdrUnloadDll, status:0x0, handl


e:0x776F0000
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x76B00000
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"C:\WINDOWS\System32\kernel32.dll", handle:0x74CD0000
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74CD0000, name:"BaseIsAppcompatInfrastructureDisabled", o
rdinal:0x0, address:0x74CEFEC0, image:0x0, caller:0x60AE3159
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\Software\Policies\Microsoft\Windows\AppCompat"
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\Software\Policies\Microsoft\Wi
ndows\AppCompat"
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtOpenSection, status:0xC00000
34, handle:0x0, access:0xF, path:"\KnownDlls32\sfc_os.dll"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x20, path:"C:\WINDOWS\System32\sfc_os.dll"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtOpenFile, status:0x0, handle:
0x5D0, access:0x100021, iostatus:0x0, information:0x1, share:0x5, options:0x60,
path:"C:\WINDOWS\System32\sfc_os.dll"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtCreateSection, status:0x0, ha
ndle:0x5BC, access:0xF, pageattribs:0x10, sectionattribs:0x1000000, file:0x5D0
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x63B00000, zerobits:0x0, commitsize:0x0, viewsize:0xF000, disposition:
0x1, type:0x800000, protect:0x4, handle:0x5BC, path:"C:\WINDOWS\System32\sfc_os.
dll"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtClose, status:0x0, handle:0x5
BC
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtClose, status:0x0, handle:0x5
D0
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"C:\WINDOWS\System32\sfc_os.dll", handle:0x63B00000
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x63B00000, name:"SfcIsFileProtected", ordinal:0x0, address
:0x63B04730, image:0x0, caller:0x60AE3262
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtOpenFile, status:0x0, handle:
0x5D0, access:0x120089, iostatus:0x0, information:0x1, share:0x1, options:0x0, p
ath:"\SystemRoot\WinSxS\FileMaps\_0000000000000000.cdf-ms"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryInformationFile, status:
0x0, iostatus:0x0, information:0x18, length:0x18, class:0x5, handle:0x5D0, path:
"\SystemRoot\WinSxS\FileMaps\_0000000000000000.cdf-ms"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtCreateSection, status:0x0, ha
ndle:0x5BC, access:0xF0005, pageattribs:0x2, sectionattribs:0x8000000, file:0x5D
0, path:""
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0xFFEA0000, zerobits:0x0, commitsize:0x0, viewsize:0x1000, disposition:
0x2, type:0x500000, protect:0x2, handle:0x5BC, path:"\SystemRoot\WinSxS\FileMaps
\_0000000000000000.cdf-ms"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtClose, status:0x0, handle:0x5
D0, path:"C:\Windows\WinSxS\FileMaps\_0000000000000000.cdf-ms"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtClose, status:0x0, handle:0x5
BC
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0xFFEA0000
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtOpenSection, status:0x0, hand
le:0x5BC, access:0xF, path:"\KnownDlls32\SETUPAPI.dll"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x770B0000, zerobits:0x0, commitsize:0x0, viewsize:0x40B000, dispositio

n:0x1, type:0x800000, protect:0x4, handle:0x5BC, path:"\KnownDlls32\Setupapi.dll


"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtClose, status:0x0, handle:0x5
BC
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x5B4, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\Curre
ntVersion\Setup"
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"SourcePath", class:0x2, length:0x10, resultlength:0x0, handle:0x5B4,
path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Windows\CurrentVersion\Setup"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtClose, status:0x0, handle:0x5
B4
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtCreateMutant, status:0x0, han
dle:0x5A0, access:0x1F0001, owner:0x0
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtCreateMutant, status:0x0, han
dle:0x5C4, access:0x1F0001, owner:0x0
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x63B00000
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtOpenSection, status:0xC00000
34, handle:0x0, access:0xF, path:"\KnownDlls32\DEVRTL.dll"
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtQueryAttributesFile, status:
0xC0000034, path:"C:\Users\i92segoa\Desktop\Firefox SEO\DEVRTL.dll"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x20, path:"C:\WINDOWS\SYSTEM32\DEVRTL.dll"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtOpenFile, status:0x0, handle:
0x5C0, access:0x100021, iostatus:0x0, information:0x1, share:0x5, options:0x60,
path:"C:\WINDOWS\SYSTEM32\DEVRTL.dll"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtCreateSection, status:0x0, ha
ndle:0x5D8, access:0xF, pageattribs:0x10, sectionattribs:0x1000000, file:0x5C0
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x60AD0000, zerobits:0x0, commitsize:0x0, viewsize:0xF000, disposition:
0x1, type:0x800000, protect:0x4, handle:0x5D8, path:"C:\WINDOWS\SYSTEM32\DEVRTL.
dll"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtClose, status:0x0, handle:0x5
D8
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtClose, status:0x0, handle:0x5
C0
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtCreateMutant, status:0x0, han
dle:0x5D8, access:0x1F0001, owner:0x0
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x770B0000
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtWaitForMultipleObjects, statu
s:0x1, count:0x2, type:0x1, alertable:0x0, objects:0x5C0;0x5D8
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtOpenKeyEx, status:0xC0000022
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\software\microsoft\windows
\currentversion\setup\PnpLockdownFiles"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtOpenFile, status:0x0, handle:
0x5DC, access:0x100000, iostatus:0x0, information:0x1, share:0x0, options:0x4021
, path:"C:\"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryInformationFile, status:
0x0, iostatus:0x0, information:0x6, length:0x210, class:0x9, handle:0x5DC, path:
"C:"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryVolumeInformationFile, s
tatus:0x0, iostatus:0x0, information:0x14, length:0x21A, class:0x5, handle:0x5DC
, path:"C:"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtClose, status:0x0, handle:0x5
DC
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtOpenFile, status:0x0, handle:
0x5DC, access:0x100000, iostatus:0x0, information:0x1, share:0x0, options:0x4021
, path:"C:\"

pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryInformationFile, status:


0x0, iostatus:0x0, information:0x6, length:0x210, class:0x9, handle:0x5DC, path:
"C:"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryVolumeInformationFile, s
tatus:0x0, iostatus:0x0, information:0x14, length:0x21A, class:0x5, handle:0x5DC
, path:"C:"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtClose, status:0x0, handle:0x5
DC
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtOpenFile, status:0x0, handle:
0x5DC, access:0x100000, iostatus:0x0, information:0x1, share:0x0, options:0x4021
, path:"C:\"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryInformationFile, status:
0x0, iostatus:0x0, information:0x6, length:0x210, class:0x9, handle:0x5DC, path:
"C:"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryVolumeInformationFile, s
tatus:0x0, iostatus:0x0, information:0x14, length:0x21A, class:0x5, handle:0x5DC
, path:"C:"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtClose, status:0x0, handle:0x5
DC
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:New_ResumeThread, ret:0x1, gle:
0x0, thread:0x5C8
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0x6E, handle:0x53A, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\exefile\shell\open"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x53A, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\exefile\shell\open"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\exefile\shell\open"
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DontReturnProcessHandle", class:0x2, length:0x90, resultlength:0x0,
handle:0x53A, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\exefile\shell\open"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtDuplicateObject, status:0x0,
targethandle:0x5DC, access:0x0, inherit:0x0, options:0x2, handle:0x5CC
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x92, handle:0x386, path:"\REGISTRY\USER\S-1-5-21
-2360094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x386, path:"\REGISTRY\USER\S-1-5-21-23
60094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001_Classes\Applications\firefox.exe"
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\Registry\Machine\Software\Classes\Applicati
ons\firefox.exe"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0x58, handle:0x576, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\exefile"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x576, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\exefile"

pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:New_NtQueryInformationToken::<l


ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\exefile"
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"AppUserModelID", class:0x2, length:0x90, resultlength:0x35002D, hand
le:0x576, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\exefile"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x58, handle:0x576, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\exefile"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x576, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\exefile"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_Classes\exefile\Application"
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\exefile\Appli
cation"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0x6E, handle:0x53A, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\exefile\shell\open"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x53A, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\exefile\shell\open"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\exefile\shell\open"
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"FriendlyAppName", class:0x2, length:0x90, resultlength:0x0, handle:0
x53A, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\exefile\shell\open"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x58, handle:0x576, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\exefile"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x576, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\exefile"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_Classes\exefile\Application"
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\exefile\Appli
cation"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x6E, handle:0x53A, path:"\REGISTRY\MACHINE\SOFTW

ARE\Classes\exefile\shell\open"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x53A, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\exefile\shell\open"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_Classes\exefile\shell\open\command"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x5E4, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\exefile\shell\open\
command"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0x7E, handle:0x5E6, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\exefile\shell\open\command"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x5E6, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\exefile\shell\open\command"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\exefile\shell\open\command"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"", class:0x2, length:0x90, resultlength:0x1C, handle:0x5E6, path:"\REGISTRY\
MACHINE\SOFTWARE\Classes\exefile\shell\open\command"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtClose, status:0x0, handle:0x5
E6
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x92, handle:0x386, path:"\REGISTRY\USER\S-1-5-21
-2360094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x386, path:"\REGISTRY\USER\S-1-5-21-23
60094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001_Classes\Applications\%1.exe"
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\Registry\Machine\Software\Classes\Applicati
ons\%1.exe"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x6E, handle:0x53A, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\exefile\shell\open"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x53A, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\exefile\shell\open"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_Classes\exefile\shell\open\command"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x5E4, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\exefile\shell\open\
command"

pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0


x3, length:0x188, resultlength:0x7E, handle:0x5E6, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\exefile\shell\open\command"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x5E6, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\exefile\shell\open\command"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\exefile\shell\open\command"
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DelegateExecute", class:0x2, length:0x90, resultlength:0x0, handle:0
x5E6, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\exefile\shell\open\command"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtClose, status:0x0, handle:0x5
E6
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x6E, handle:0x53A, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\exefile\shell\open"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x53A, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\exefile\shell\open"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_Classes\exefile\shell\open\DropTarget"
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\exefile\shell
\open\DropTarget"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x6E, handle:0x53A, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\exefile\shell\open"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x53A, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\exefile\shell\open"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_Classes\exefile\shell\open\command"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x5E4, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\exefile\shell\open\
command"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0x7E, handle:0x5E6, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\exefile\shell\open\command"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x5E6, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\exefile\shell\open\command"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0

pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034


, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\exefile\shell\open\command"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"", class:0x2, length:0x90, resultlength:0x1C, handle:0x5E6, path:"\REGISTRY\
MACHINE\SOFTWARE\Classes\exefile\shell\open\command"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtClose, status:0x0, handle:0x5
E6
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001\Software\Microsoft\Windows\CurrentVersion\App Paths\%1.exe"
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows
\CurrentVersion\App Paths\%1.exe"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x58, handle:0x576, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\exefile"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x576, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\exefile"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_Classes\exefile\Progid"
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\exefile\Progi
d"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtClose, status:0x0, handle:0x5
CC
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtClose, status:0x0, handle:0x5
C8
pid:4092, tid:2168, tick:0x33D70DA, lvl:WRN, func:NtClose, status:0xC0000008
pid:4092, tid:2168, tick:0x33D70DA, lvl:WRN, func:NtClose, status:0xC0000008
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"ntdll.dll", module:0x77C10000
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77C10000, name:"RtlDllShutdownInProgress", ordinal:0x0, a
ddress:0x77C3C5E0, image:0x0, caller:0x76CDF21F
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtClose, status:0x0, handle:0x5
66
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x564, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{9AC9FBE1-E
0A2-4AD6-B4EE-E212013EA917}"
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"AppID", class:0x2, length:0x400, resultlength:0x0, handle:0x564, pat
h:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE
-E212013EA917}"
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtOpenKey, status:0xC0000034,
handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node
\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}\LocalServer32"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtClose, status:0x0, handle:0x5
64
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x92, handle:0x3C2, path:"\Registry\User\S-1-5-21
-2360094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x3C2, path:"\Registry\User\S-1-5-21-23

60094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\Registry\User\S-1-5-21-2360094602-260238339
7-2463990887-1001_Classes\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x564, access:0x20019, path:"\Registry\Machine\Software\Classes\CLSID\{9AC9FBE1
-E0A2-4AD6-B4EE-E212013EA917}"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0xBA, handle:0x566, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x566, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_Classes\WOW6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}\T
reatAs"
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\C
LSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}\TreatAs"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x204, resultlength:0xBA, handle:0x566, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0xBA, handle:0x566, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x566, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\WOW6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA
917}"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"", class:0x2, length:0x90, resultlength:0x4E, handle:0x566, path:"\REGISTRY\
MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917
}"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0xBA, handle:0x566, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x566, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\WOW6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA
917}"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryValueKey, status:0x0, na

me:"", class:0x2, length:0x90, resultlength:0x4E, handle:0x566, path:"\REGISTRY\


MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917
}"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0xBA, handle:0x566, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x566, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001_Classes\WOW6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA91
7}\InprocServer32"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x5C8, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLS
ID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}\InprocServer32"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0xD8, handle:0x5CA, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}\InProcServe
r32"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x5CA, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}\InProcServer32
"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\WOW6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA
917}\InProcServer32"
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"InprocServer32", class:0x2, length:0x90, resultlength:0x0, handle:0x
5CA, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{9AC9FBE1-E0A2-4
AD6-B4EE-E212013EA917}\InProcServer32"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0xD8, handle:0x5CA, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}\InProcServe
r32"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x5CA, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}\InProcServer32
"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\WOW6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA
917}\InProcServer32"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"", class:0x2, length:0x90, resultlength:0x60, handle:0x5CA, path:"\REGISTRY\
MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917
}\InProcServer32"

pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0


x3, length:0x188, resultlength:0xD8, handle:0x5CA, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}\InProcServe
r32"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x5CA, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}\InProcServer32
"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\WOW6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA
917}\InProcServer32"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"", class:0x2, length:0x90, resultlength:0x60, handle:0x5CA, path:"\REGISTRY\
MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917
}\InProcServer32"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0xD8, handle:0x5CA, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}\InProcServe
r32"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x5CA, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}\InProcServer32
"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\WOW6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA
917}\InProcServer32"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"", class:0x2, length:0x90, resultlength:0x60, handle:0x5CA, path:"\REGISTRY\
MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917
}\InProcServer32"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0xD8, handle:0x5CA, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}\InProcServe
r32"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x5CA, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}\InProcServer32
"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\WOW6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA
917}\InProcServer32"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ThreadingModel", class:0x2, length:0x90, resultlength:0x16, handle:0x5CA, pa
th:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4E
E-E212013EA917}\InProcServer32"

pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtClose, status:0x0, handle:0x5


CA
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0xBA, handle:0x566, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x566, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_Classes\WOW6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}\I
nprocHandler32"
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\C
LSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}\InprocHandler32"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0xBA, handle:0x566, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x566, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_Classes\WOW6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}\I
nprocHandler"
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\C
LSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}\InprocHandler"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtClose, status:0x0, handle:0x5
66
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x92, handle:0x422, path:"\Registry\User\S-1-5-21
-2360094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x422, path:"\Registry\User\S-1-5-21-23
60094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\Registry\User\S-1-5-21-2360094602-260238339
7-2463990887-1001_Classes\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x564, access:0x20019, path:"\Registry\Machine\Software\Classes\CLSID\{9AC9FBE1
-E0A2-4AD6-B4EE-E212013EA917}"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0xBA, handle:0x566, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x566, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0

pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034


, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001_Classes\WOW6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA91
7}\TreatAs"
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432No
de\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}\TreatAs"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtClose, status:0x0, handle:0x5
66
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:CoCreateInstance, hr:0x0, clsid
:9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917, context:0x403, riid:00000003-0000-0000-C0
00-000000000046
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtClose, status:0x0, handle:0x5
5A
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtClose, status:0x0, handle:0x5
76
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtClose, status:0x0, handle:0x5
3A
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x74DC0000
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtUnmapViewOfSectionEx, status:
0x0, address:0x670000
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtClose, status:0x0, handle:0x3
B4
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtClose, status:0x0, handle:0x3
C2
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:LdrUnloadDll, status:0x0, handl
e:0x717E0000
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:LdrUnloadDll, status:0x0, handl
e:0x76B00000
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:LdrUnloadDll, status:0x0, handl
e:0x73500000
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"oleaut32.dll", module:0x754E0000
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x74DC0000
pid:4092, tid:2168, tick:0x33D70DA, lvl:WRN, func:NtClose, status:0xC0000008
pid:4092, tid:2168, tick:0x33D70DA, lvl:WRN, func:NtClose, status:0xC0000008
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:ShellExecuteExW, ret:0x1, gle:0
x0, verb:"open", file:"\"C:\Program Files (x86)\Mozilla Firefox\firefox.exe\"",
mask:0x8140
pid:4092, tid:8264, tick:0x33D70EA, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x514, iostatus:0x0, information:0xA4, code:0x1203F, inlen:0x0, outlen
:0x10, handle:0x55C, path:"\Device\Afd\Endpoint"
pid:4092, tid:8264, tick:0x33D70EA, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x514, iostatus:0x0, information:0x0, code:0x12047, inlen:0xA4, outlen
:0x0, handle:0x55C, path:"\Device\Afd\Endpoint"
pid:4092, tid:8264, tick:0x33D70EA, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x514, iostatus:0x0, information:0x0, code:0x1203B, inlen:0x10, outlen
:0x0, handle:0x55C, path:"\Device\Afd\Endpoint"
pid:4092, tid:8264, tick:0x33D70EA, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x514, iostatus:0x0, information:0x0, code:0x12047, inlen:0xA4, outlen
:0x0, handle:0x55C, path:"\Device\Afd\Endpoint"
pid:4092, tid:8264, tick:0x33D70EA, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x514, iostatus:0x0, information:0x10, code:0x1202F, inlen:0x0, outlen
:0x10, handle:0x55C, path:"\Device\Afd\Endpoint"
pid:4092, tid:1488, tick:0x33D70EA, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x50C, iostatus:0x0, information:0xA4, code:0x1203F, inlen:0x0, outlen
:0x10, handle:0x53C, path:"\Device\Afd\Endpoint"
pid:4092, tid:1488, tick:0x33D70EA, lvl:OK, func:NtDeviceIoControlFile, status:0

x0, event:0x50C, iostatus:0x0, information:0x0, code:0x12047, inlen:0xA4, outlen


:0x0, handle:0x53C, path:"\Device\Afd\Endpoint"
pid:4092, tid:1488, tick:0x33D70EA, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x50C, iostatus:0x0, information:0x0, code:0x1203B, inlen:0x10, outlen
:0x0, handle:0x53C, path:"\Device\Afd\Endpoint"
pid:4092, tid:1488, tick:0x33D70EA, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x50C, iostatus:0x0, information:0x0, code:0x12047, inlen:0xA4, outlen
:0x0, handle:0x53C, path:"\Device\Afd\Endpoint"
pid:4092, tid:1488, tick:0x33D70EA, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x50C, iostatus:0x0, information:0x10, code:0x1202F, inlen:0x0, outlen
:0x10, handle:0x53C, path:"\Device\Afd\Endpoint"
pid:4092, tid:8264, tick:0x33D70EA, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x5EC, access:0x20019, path:"\REGISTRY\MACHINE\System\CurrentControlSet\Control
\SecurityProviders"
pid:4092, tid:8264, tick:0x33D70EA, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"SecurityProviders", class:0x2, length:0x90, resultlength:0x24, handle:0x5EC,
path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\SecurityProviders"
pid:4092, tid:8264, tick:0x33D70EA, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"SecurityProviders", class:0x2, length:0x90, resultlength:0x24, handle:0x5EC,
path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\SecurityProviders"
pid:4092, tid:8264, tick:0x33D70EA, lvl:OK, func:NtClose, status:0x0, handle:0x5
EC
pid:4092, tid:8264, tick:0x33D70EA, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x5EC, access:0x20019, path:"\REGISTRY\MACHINE\System\CurrentControlSet\Control
\Lsa\SspiCache"
pid:4092, tid:8264, tick:0x33D70EA, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x5F0, access:0x20019, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
\SspiCache\credssp.dll"
pid:4092, tid:8264, tick:0x33D70EA, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Name", class:0x2, length:0x90, resultlength:0x1C, handle:0x5F0, path:"\REGIS
TRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll"
pid:4092, tid:8264, tick:0x33D70EA, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Name", class:0x2, length:0x90, resultlength:0x1C, handle:0x5F0, path:"\REGIS
TRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll"
pid:4092, tid:8264, tick:0x33D70EA, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Comment", class:0x2, length:0x90, resultlength:0x54, handle:0x5F0, path:"\RE
GISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll"
pid:4092, tid:8264, tick:0x33D70EA, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Comment", class:0x2, length:0x90, resultlength:0x54, handle:0x5F0, path:"\RE
GISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll"
pid:4092, tid:8264, tick:0x33D70EA, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Capabilities", class:0x2, length:0x90, resultlength:0x10, handle:0x5F0, path
:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll"
pid:4092, tid:8264, tick:0x33D70EA, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"RpcId", class:0x2, length:0x90, resultlength:0x10, handle:0x5F0, path:"\REGI
STRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll"
pid:4092, tid:8264, tick:0x33D70EA, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Version", class:0x2, length:0x90, resultlength:0x10, handle:0x5F0, path:"\RE
GISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll"
pid:4092, tid:8264, tick:0x33D70EA, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Type", class:0x2, length:0x90, resultlength:0x10, handle:0x5F0, path:"\REGIS
TRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll"
pid:4092, tid:8264, tick:0x33D70EA, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"TokenSize", class:0x2, length:0x90, resultlength:0x10, handle:0x5F0, path:"\
REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll"
pid:4092, tid:8264, tick:0x33D70EA, lvl:OK, func:NtClose, status:0x0, handle:0x5
EC
pid:4092, tid:8264, tick:0x33D70EA, lvl:OK, func:NtClose, status:0x0, handle:0x5
F0
pid:4092, tid:8264, tick:0x33D70EA, lvl:OK, func:NtOpenKeyEx, status:0x0, handle

:0x5F0, access:0x20019, path:"\REGISTRY\MACHINE\System\CurrentControlSet\Control


\SecurityProviders\SaslProfiles"
pid:4092, tid:8264, tick:0x33D70EA, lvl:OK, func:NtEnumerateValueKey, status:0x0
, index:0x0, class:0x1, length:0x410, resultlength:0x32, handle:0x5F0, path:"\RE
GISTRY\MACHINE\SYSTEM\ControlSet001\Control\SecurityProviders\SaslProfiles"
pid:4092, tid:8264, tick:0x33D70EA, lvl:LOG, func:NtEnumerateValueKey, status:0x
8000001A, index:0x1, class:0x1, length:0x410, resultlength:0x32, handle:0x5F0, p
ath:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\SecurityProviders\SaslProfil
es"
pid:4092, tid:8264, tick:0x33D70EA, lvl:OK, func:NtClose, status:0x0, handle:0x5
F0
pid:4092, tid:8264, tick:0x33D70EA, lvl:LOG, func:NtOpenSection, status:0xC00000
34, handle:0x0, access:0xF, path:"\KnownDlls32\schannel.dll"
pid:4092, tid:8264, tick:0x33D70EA, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x20, path:"C:\WINDOWS\SYSTEM32\schannel.dll"
pid:4092, tid:8264, tick:0x33D70EA, lvl:OK, func:NtOpenFile, status:0x0, handle:
0x5F8, access:0x100021, iostatus:0x0, information:0x1, share:0x5, options:0x60,
path:"C:\WINDOWS\SYSTEM32\schannel.dll"
pid:4092, tid:8264, tick:0x33D70EA, lvl:OK, func:NtCreateSection, status:0x0, ha
ndle:0x5FC, access:0xF, pageattribs:0x10, sectionattribs:0x1000000, file:0x5F8
pid:4092, tid:8264, tick:0x33D70EA, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x6D390000, zerobits:0x0, commitsize:0x0, viewsize:0x64000, disposition
:0x1, type:0x800000, protect:0x4, handle:0x5FC, path:"C:\WINDOWS\SYSTEM32\schann
el.dll"
pid:4092, tid:8264, tick:0x33D70EA, lvl:OK, func:NtClose, status:0x0, handle:0x5
FC
pid:4092, tid:8264, tick:0x33D70EA, lvl:OK, func:NtClose, status:0x0, handle:0x5
F8
pid:4092, tid:8264, tick:0x33D70EA, lvl:OK, func:NtCreateSemaphore, status:0x0,
handle:0x5F8, access:0x100003, initialcount:0x0, maxcount:0x7FFFFFFF
pid:4092, tid:8264, tick:0x33D70EA, lvl:OK, func:NtCreateSemaphore, status:0x0,
handle:0x5FC, access:0x100003, initialcount:0x0, maxcount:0x7FFFFFFF
pid:4092, tid:8264, tick:0x33D70EA, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"schannel", module:0x6D390000
pid:4092, tid:8264, tick:0x33D70EA, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"C:\WINDOWS\SysWOW64\schannel.dll", handle:0x6D390000
pid:4092, tid:8264, tick:0x33D70EA, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x6D390000, name:"SpUserModeInitialize", ordinal:0x0, addre
ss:0x6D3A6B10, image:0x0, caller:0x7494D82A
pid:4092, tid:8264, tick:0x33D70EA, lvl:OK, func:NtCreateKey, status:0x0, handle
:0x608, access:0x20019, title:0x0, class:"", options:0x0, disposition:0x2, path:
"\REGISTRY\MACHINE\System\CurrentControlSet\Control\SecurityProviders\Schannel"
pid:4092, tid:8264, tick:0x33D70EA, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"UserContextLockCount", class:0x2, length:0x90, resultlength:0x0, han
dle:0x608, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\SecurityProvider
s\SCHANNEL"
pid:4092, tid:8264, tick:0x33D70EA, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"UserContextListCount", class:0x2, length:0x90, resultlength:0x0, han
dle:0x608, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\SecurityProvider
s\SCHANNEL"
pid:4092, tid:8264, tick:0x33D70EA, lvl:OK, func:NtClose, status:0x0, handle:0x6
08
pid:4092, tid:8264, tick:0x33D70EA, lvl:OK, func:NtCreateSemaphore, status:0x0,
handle:0x608, access:0x100003, initialcount:0x0, maxcount:0x7FFFFFFF
pid:4092, tid:8264, tick:0x33D70EA, lvl:OK, func:NtCreateSemaphore, status:0x0,
handle:0x60C, access:0x100003, initialcount:0x0, maxcount:0x7FFFFFFF
pid:4092, tid:8264, tick:0x33D70EA, lvl:OK, func:NtCreateSemaphore, status:0x0,
handle:0x610, access:0x100003, initialcount:0x0, maxcount:0x7FFFFFFF
pid:4092, tid:8264, tick:0x33D70EA, lvl:OK, func:NtCreateSemaphore, status:0x0,
handle:0x614, access:0x100003, initialcount:0x0, maxcount:0x7FFFFFFF

pid:4092, tid:8264, tick:0x33D70EA, lvl:OK, func:NtCreateSemaphore, status:0x0,


handle:0x618, access:0x100003, initialcount:0x0, maxcount:0x7FFFFFFF
pid:4092, tid:8264, tick:0x33D70EA, lvl:OK, func:NtCreateSemaphore, status:0x0,
handle:0x61C, access:0x100003, initialcount:0x0, maxcount:0x7FFFFFFF
pid:4092, tid:8264, tick:0x33D70EA, lvl:OK, func:NtCreateSemaphore, status:0x0,
handle:0x620, access:0x100003, initialcount:0x0, maxcount:0x7FFFFFFF
pid:4092, tid:8264, tick:0x33D70EA, lvl:OK, func:NtCreateSemaphore, status:0x0,
handle:0x624, access:0x100003, initialcount:0x0, maxcount:0x7FFFFFFF
pid:4092, tid:8264, tick:0x33D70EA, lvl:OK, func:NtCreateSemaphore, status:0x0,
handle:0x628, access:0x100003, initialcount:0x0, maxcount:0x7FFFFFFF
pid:4092, tid:8264, tick:0x33D70EA, lvl:OK, func:NtCreateSemaphore, status:0x0,
handle:0x62C, access:0x100003, initialcount:0x0, maxcount:0x7FFFFFFF
pid:4092, tid:8264, tick:0x33D70EA, lvl:OK, func:NtCreateSemaphore, status:0x0,
handle:0x630, access:0x100003, initialcount:0x0, maxcount:0x7FFFFFFF
pid:4092, tid:8264, tick:0x33D70EA, lvl:OK, func:NtCreateSemaphore, status:0x0,
handle:0x634, access:0x100003, initialcount:0x0, maxcount:0x7FFFFFFF
pid:4092, tid:8264, tick:0x33D70EA, lvl:OK, func:NtCreateSemaphore, status:0x0,
handle:0x638, access:0x100003, initialcount:0x0, maxcount:0x7FFFFFFF
pid:4092, tid:8264, tick:0x33D70EA, lvl:OK, func:NtCreateSemaphore, status:0x0,
handle:0x63C, access:0x100003, initialcount:0x0, maxcount:0x7FFFFFFF
pid:4092, tid:8264, tick:0x33D70EA, lvl:OK, func:NtCreateSemaphore, status:0x0,
handle:0x640, access:0x100003, initialcount:0x0, maxcount:0x7FFFFFFF
pid:4092, tid:8264, tick:0x33D70EA, lvl:OK, func:NtCreateSemaphore, status:0x0,
handle:0x644, access:0x100003, initialcount:0x0, maxcount:0x7FFFFFFF
pid:4092, tid:8264, tick:0x33D70EA, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, iostatus:0x0, information:0xC0, code:0x1201F, inlen:0x10, outlen:0x0, handle
:0x55C, path:"\Device\Afd\Endpoint"
pid:4092, tid:1488, tick:0x33D70EA, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, iostatus:0x0, information:0xC0, code:0x1201F, inlen:0x10, outlen:0x0, handle
:0x53C, path:"\Device\Afd\Endpoint"
pid:4092, tid:8264, tick:0x33D70EA, lvl:OK, func:NtDeviceIoControlFile, status:0
x103, iostatus:0x103, information:0x0, code:0x12017, inlen:0x10, outlen:0x0, han
dle:0x55C, path:"\Device\Afd\Endpoint"
pid:4092, tid:1488, tick:0x33D70EA, lvl:OK, func:NtDeviceIoControlFile, status:0
x103, iostatus:0x103, information:0x0, code:0x12017, inlen:0x10, outlen:0x0, han
dle:0x53C, path:"\Device\Afd\Endpoint"
pid:4092, tid:1488, tick:0x33D71B5, lvl:OK, func:NtDeviceIoControlFile, status:0
x103, iostatus:0x103, information:0x0, code:0x12017, inlen:0x10, outlen:0x0, han
dle:0x53C, path:"\Device\Afd\Endpoint"
pid:4092, tid:1488, tick:0x33D71B5, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, iostatus:0x0, information:0x498, code:0x12017, inlen:0x10, outlen:0x0, handl
e:0x53C, path:"\Device\Afd\Endpoint"
pid:4092, tid:1488, tick:0x33D71B5, lvl:OK, func:NtDeviceIoControlFile, status:0
x103, iostatus:0x103, information:0x0, code:0x12017, inlen:0x10, outlen:0x0, han
dle:0x53C, path:"\Device\Afd\Endpoint"
pid:4092, tid:1488, tick:0x33D71B5, lvl:OK, func:NtDeviceIoControlFile, status:0
x103, iostatus:0x103, information:0x0, code:0x12017, inlen:0x10, outlen:0x0, han
dle:0x53C, path:"\Device\Afd\Endpoint"
pid:4092, tid:1488, tick:0x33D71B5, lvl:OK, func:NtDeviceIoControlFile, status:0
x103, iostatus:0x103, information:0x0, code:0x12017, inlen:0x10, outlen:0x0, han
dle:0x55C, path:"\Device\Afd\Endpoint"
pid:4092, tid:1488, tick:0x33D71B5, lvl:OK, func:NtDeviceIoControlFile, status:0
x103, iostatus:0x103, information:0x0, code:0x12017, inlen:0x10, outlen:0x0, han
dle:0x55C, path:"\Device\Afd\Endpoint"
pid:4092, tid:1488, tick:0x33D71B5, lvl:OK, func:NtDeviceIoControlFile, status:0
x103, iostatus:0x103, information:0x0, code:0x12017, inlen:0x10, outlen:0x0, han
dle:0x55C, path:"\Device\Afd\Endpoint"
pid:4092, tid:1488, tick:0x33D71B5, lvl:OK, func:NtDeviceIoControlFile, status:0
x103, iostatus:0x103, information:0x0, code:0x12017, inlen:0x10, outlen:0x0, han
dle:0x55C, path:"\Device\Afd\Endpoint"

pid:4092, tid:1488, tick:0x33D7261, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x498, iocompletion:0x38, handle:0x460
pid:4092, tid:1488, tick:0x33D7261, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x648, iostatus:0x0, information:0x50, code:0x120007, inlen:0x30, outl
en:0x4, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:1488, tick:0x33D7261, lvl:OK, func:NtClose, status:0x0, handle:0x6
48
pid:4092, tid:1488, tick:0x33D7261, lvl:OK, func:WSAStartup, ret:0x0, gle:0x0, V
ersionRequested:0x202, Version:0x202, Description:"WinSock 2.0", SystemStatus:"R
unning", MaxSockets:0x0, MaxUdpDg:0x0
pid:4092, tid:1488, tick:0x33D7261, lvl:OK, func:NtCreateFile, status:0x0, handl
e:0x648, access:0xC0140000, iostatus:0x0, information:0x0, attribs:0x0, share:0x
3, disposition:0x3, options:0x0, path:"\Device\Afd\Endpoint"
pid:4092, tid:1488, tick:0x33D7261, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x50C, iostatus:0x0, information:0x0, code:0x12047, inlen:0xC4, outlen
:0x1C, handle:0x648, path:"\Device\Afd\Endpoint"
pid:4092, tid:1488, tick:0x33D7261, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x50C, iostatus:0x0, information:0x0, code:0x120BF, inlen:0x18, outlen
:0x0, handle:0x648, path:"\Device\Afd\Endpoint"
pid:4092, tid:1488, tick:0x33D7261, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x50C, iostatus:0x0, information:0x0, code:0x12047, inlen:0xC4, outlen
:0x1C, handle:0x648, path:"\Device\Afd\Endpoint"
pid:4092, tid:1488, tick:0x33D7261, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x50C, iostatus:0x0, information:0xB8, code:0x120B3, inlen:0x2, outlen
:0x200, handle:0x648, path:"\Device\Afd\Endpoint"
pid:4092, tid:1488, tick:0x33D7261, lvl:OK, func:NtDeviceIoControlFile, status:0
x103, event:0x50C, iostatus:0x0, information:0x34, code:0x120BF, inlen:0x18, out
len:0xDC, handle:0x648, path:"\Device\Afd\Endpoint"
pid:4092, tid:1488, tick:0x33D7261, lvl:OK, func:NtClose, status:0x0, handle:0x6
48
pid:4092, tid:8264, tick:0x33D7261, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x458, iocompletion:0x38, handle:0x410
pid:4092, tid:8264, tick:0x33D7261, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x648, iostatus:0x0, information:0x50, code:0x120007, inlen:0x30, outl
en:0x4, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:8264, tick:0x33D7261, lvl:OK, func:NtClose, status:0x0, handle:0x6
48
pid:4092, tid:8264, tick:0x33D7261, lvl:OK, func:WSAStartup, ret:0x0, gle:0x0, V
ersionRequested:0x202, Version:0x202, Description:"WinSock 2.0", SystemStatus:"R
unning", MaxSockets:0x0, MaxUdpDg:0x0
pid:4092, tid:8264, tick:0x33D7261, lvl:OK, func:NtCreateFile, status:0x0, handl
e:0x3C0, access:0xC0140000, iostatus:0x0, information:0x0, attribs:0x0, share:0x
3, disposition:0x3, options:0x0, path:"\Device\Afd\Endpoint"
pid:4092, tid:8264, tick:0x33D7261, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x514, iostatus:0x0, information:0x0, code:0x12047, inlen:0xC4, outlen
:0x1C, handle:0x3C0, path:"\Device\Afd\Endpoint"
pid:4092, tid:8264, tick:0x33D7261, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x514, iostatus:0x0, information:0x0, code:0x120BF, inlen:0x18, outlen
:0x0, handle:0x3C0, path:"\Device\Afd\Endpoint"
pid:4092, tid:8264, tick:0x33D7261, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x514, iostatus:0x0, information:0x0, code:0x12047, inlen:0xC4, outlen
:0x1C, handle:0x3C0, path:"\Device\Afd\Endpoint"
pid:4092, tid:8264, tick:0x33D7261, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x514, iostatus:0x0, information:0xB8, code:0x120B3, inlen:0x2, outlen
:0x200, handle:0x3C0, path:"\Device\Afd\Endpoint"
pid:4092, tid:8264, tick:0x33D7261, lvl:OK, func:NtDeviceIoControlFile, status:0
x103, event:0x514, iostatus:0x0, information:0x34, code:0x120BF, inlen:0x18, out
len:0xDC, handle:0x3C0, path:"\Device\Afd\Endpoint"
pid:4092, tid:8264, tick:0x33D7261, lvl:OK, func:NtClose, status:0x0, handle:0x3
C0

pid:4092, tid:8264, tick:0x33D7270, lvl:OK, func:NtCreateSemaphore, status:0x0,


handle:0x648, access:0x1F0003, initialcount:0x0, maxcount:0x7FFFFF
pid:4092, tid:1488, tick:0x33D7270, lvl:OK, func:NtCreateSemaphore, status:0x0,
handle:0x5A8, access:0x1F0003, initialcount:0x0, maxcount:0x7FFFFF
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtCreateSemaphore, status:0x0,
handle:0x64C, access:0x100003, initialcount:0x0, maxcount:0x7FFFFFFF
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtCreateSemaphore, status:0x0,
handle:0x650, access:0x100003, initialcount:0x0, maxcount:0x7FFFFFFF
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"sspicli.dll", handle:0x74940000
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74940000, name:"FreeContextBuffer", ordinal:0x0, address:
0x7494B3C0, image:0x0, caller:0x6D3A6B53
pid:4092, tid:8264, tick:0x33D7280, lvl:LOG, func:NtOpenSection, status:0xC00000
34, handle:0x0, access:0xF, path:"\KnownDlls32\mskeyprotect.dll"
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x20, path:"C:\WINDOWS\SYSTEM32\mskeyprotect.dll"
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtOpenFile, status:0x0, handle:
0x654, access:0x100021, iostatus:0x0, information:0x1, share:0x5, options:0x60,
path:"C:\WINDOWS\SYSTEM32\mskeyprotect.dll"
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtCreateSection, status:0x0, ha
ndle:0x658, access:0xF, pageattribs:0x10, sectionattribs:0x1000000, file:0x654
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x6D380000, zerobits:0x0, commitsize:0x0, viewsize:0x10000, disposition
:0x1, type:0x800000, protect:0x4, handle:0x658, path:"C:\WINDOWS\SYSTEM32\mskeyp
rotect.dll"
pid:4092, tid:8264, tick:0x33D7280, lvl:LOG, func:NtOpenSection, status:0xC00000
34, handle:0x0, access:0xF, path:"\KnownDlls32\ncrypt.dll"
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtClose, status:0x0, handle:0x6
58
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtClose, status:0x0, handle:0x6
54
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x20, path:"C:\WINDOWS\SYSTEM32\ncrypt.dll"
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtOpenFile, status:0x0, handle:
0x65C, access:0x100021, iostatus:0x0, information:0x1, share:0x5, options:0x60,
path:"C:\WINDOWS\SYSTEM32\ncrypt.dll"
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtCreateSection, status:0x0, ha
ndle:0x660, access:0xF, pageattribs:0x10, sectionattribs:0x1000000, file:0x65C
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x64B60000, zerobits:0x0, commitsize:0x0, viewsize:0x20000, disposition
:0x1, type:0x800000, protect:0x4, handle:0x660, path:"C:\WINDOWS\SYSTEM32\ncrypt
.dll"
pid:4092, tid:8264, tick:0x33D7280, lvl:LOG, func:NtOpenSection, status:0xC00000
34, handle:0x0, access:0xF, path:"\KnownDlls32\NTASN1.dll"
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtClose, status:0x0, handle:0x6
60
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtClose, status:0x0, handle:0x6
5C
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x20, path:"C:\WINDOWS\SYSTEM32\NTASN1.dll"
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtOpenFile, status:0x0, handle:
0x65C, access:0x100021, iostatus:0x0, information:0x1, share:0x5, options:0x60,
path:"C:\WINDOWS\SYSTEM32\NTASN1.dll"
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtCreateSection, status:0x0, ha
ndle:0x660, access:0xF, pageattribs:0x10, sectionattribs:0x1000000, file:0x65C
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x64B30000, zerobits:0x0, commitsize:0x0, viewsize:0x2C000, disposition
:0x1, type:0x800000, protect:0x4, handle:0x660, path:"C:\WINDOWS\SYSTEM32\NTASN1
.dll"

pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtClose, status:0x0, handle:0x6


60
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtClose, status:0x0, handle:0x6
5C
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x6D380000
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"mskeyprotect.dll", handle:0x6D380000
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x6D380000, name:"KeyFileProtectSessionTicket", ordinal:0x0
, address:0x6D386AD0, image:0x0, caller:0x6D3A6B7F
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x6D380000, name:"KeyFileUnprotectSessionTicket", ordinal:0
x0, address:0x6D386EB0, image:0x0, caller:0x6D3A6B95
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x660, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptography\
OID"
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x0, class:0x0, length:0x120, resultlength:0x2C, handle:0x660, path:"\REGISTR
Y\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID"
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x664, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\C
ryptography\OID\EncodingType 0"
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x668, access:0x20019, path:"\Registry\Machine\System\CurrentControlSet\Control\N
ls\CustomLocale"
pid:4092, tid:8264, tick:0x33D7280, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"en-US", class:0x1, length:0x214, resultlength:0xA5B5A8CA, handle:0x6
68, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale"
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtClose, status:0x0, handle:0x6
68
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x668, access:0x20019, path:"\Registry\Machine\System\CurrentControlSet\Control\N
ls\ExtendedLocale"
pid:4092, tid:8264, tick:0x33D7280, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"en-US", class:0x1, length:0x214, resultlength:0xA5B5A8CA, handle:0x6
68, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale"
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtClose, status:0x0, handle:0x6
68
pid:4092, tid:8264, tick:0x33D7280, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"en-US", class:0x2, length:0x5A, resultlength:0x345E2E2, handle:0xA4,
path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Nls\Sorting\Ids"
pid:4092, tid:8264, tick:0x33D7280, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"en", class:0x2, length:0x5A, resultlength:0x345E2E2, handle:0xA4, pa
th:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Nls\Sorting\Ids"
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x668, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\C
ryptography\OID\EncodingType 0\CertDllOpenStoreProv"
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x0, class:0x0, length:0x120, resultlength:0x16, handle:0x668, path:"\REGISTR
Y\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDll
OpenStoreProv"
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x66C, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\C
ryptography\OID\EncodingType 0\CertDllOpenStoreProv\#16"
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtQueryKey, status:0x0, class:0
x4, length:0xB0, resultlength:0x28, handle:0x66C, path:"\REGISTRY\MACHINE\SOFTWA
RE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\#1
6"
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtEnumerateValueKey, status:0x0

, index:0x0, class:0x1, length:0xDC, resultlength:0x62, handle:0x66C, path:"\REG


ISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\Cer
tDllOpenStoreProv\#16"
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtEnumerateValueKey, status:0x0
, index:0x1, class:0x1, length:0xDC, resultlength:0x4C, handle:0x66C, path:"\REG
ISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\Cer
tDllOpenStoreProv\#16"
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtClose, status:0x0, handle:0x6
6C
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1, class:0x0, length:0x120, resultlength:0x18, handle:0x668, path:"\REGISTR
Y\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDll
OpenStoreProv"
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x66C, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\C
ryptography\OID\EncodingType 0\CertDllOpenStoreProv\Ldap"
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtQueryKey, status:0x0, class:0
x4, length:0xB0, resultlength:0x28, handle:0x66C, path:"\REGISTRY\MACHINE\SOFTWA
RE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\Ld
ap"
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtEnumerateValueKey, status:0x0
, index:0x0, class:0x1, length:0xDC, resultlength:0x62, handle:0x66C, path:"\REG
ISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\Cer
tDllOpenStoreProv\Ldap"
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtEnumerateValueKey, status:0x0
, index:0x1, class:0x1, length:0xDC, resultlength:0x4C, handle:0x66C, path:"\REG
ISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\Cer
tDllOpenStoreProv\Ldap"
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtClose, status:0x0, handle:0x6
6C
pid:4092, tid:8264, tick:0x33D7280, lvl:LOG, func:NtEnumerateKey, status:0x80000
01A, index:0x2, class:0x0, length:0x120, resultlength:0x0, handle:0x668, path:"\
REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\
CertDllOpenStoreProv"
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtClose, status:0x0, handle:0x6
68
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtClose, status:0x0, handle:0x6
64
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1, class:0x0, length:0x120, resultlength:0x2C, handle:0x660, path:"\REGISTR
Y\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID"
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x664, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\C
ryptography\OID\EncodingType 1"
pid:4092, tid:8264, tick:0x33D7280, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Micro
soft\Cryptography\OID\EncodingType 1\CertDllOpenStoreProv"
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtClose, status:0x0, handle:0x6
64
pid:4092, tid:8264, tick:0x33D7280, lvl:LOG, func:NtEnumerateKey, status:0x80000
01A, index:0x2, class:0x0, length:0x120, resultlength:0x0, handle:0x660, path:"\
REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID"
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtClose, status:0x0, handle:0x6
60
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x538, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptography\
OID"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x0, class:0x0, length:0x120, resultlength:0x2C, handle:0x538, path:"\REGISTR
Y\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID"

pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtOpenKeyEx, status:0x0, handle


:0x574, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\C
ryptography\OID\EncodingType 0"
pid:4092, tid:1488, tick:0x33D7280, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Micro
soft\Cryptography\OID\EncodingType 0\CryptDllDecodeObjectEx"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtClose, status:0x0, handle:0x5
74
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1, class:0x0, length:0x120, resultlength:0x2C, handle:0x538, path:"\REGISTR
Y\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x574, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\C
ryptography\OID\EncodingType 1"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x564, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\C
ryptography\OID\EncodingType 1\CryptDllDecodeObjectEx"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x0, class:0x0, length:0x120, resultlength:0x42, handle:0x564, path:"\REGISTR
Y\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDl
lDecodeObjectEx"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x5C8, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\C
ryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.1.1"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtQueryKey, status:0x0, class:0
x4, length:0xB0, resultlength:0x28, handle:0x5C8, path:"\REGISTRY\MACHINE\SOFTWA
RE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\
1.2.840.113549.1.9.16.1.1"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtEnumerateValueKey, status:0x0
, index:0x0, class:0x1, length:0xDC, resultlength:0x62, handle:0x5C8, path:"\REG
ISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\Cry
ptDllDecodeObjectEx\1.2.840.113549.1.9.16.1.1"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtEnumerateValueKey, status:0x0
, index:0x1, class:0x1, length:0xDC, resultlength:0x4E, handle:0x5C8, path:"\REG
ISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\Cry
ptDllDecodeObjectEx\1.2.840.113549.1.9.16.1.1"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtClose, status:0x0, handle:0x5
C8
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1, class:0x0, length:0x120, resultlength:0x42, handle:0x564, path:"\REGISTR
Y\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDl
lDecodeObjectEx"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x5C8, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\C
ryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.1"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtQueryKey, status:0x0, class:0
x4, length:0xB0, resultlength:0x28, handle:0x5C8, path:"\REGISTRY\MACHINE\SOFTWA
RE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\
1.2.840.113549.1.9.16.2.1"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtEnumerateValueKey, status:0x0
, index:0x0, class:0x1, length:0xDC, resultlength:0x62, handle:0x5C8, path:"\REG
ISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\Cry
ptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.1"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtEnumerateValueKey, status:0x0
, index:0x1, class:0x1, length:0xDC, resultlength:0x5C, handle:0x5C8, path:"\REG
ISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\Cry
ptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.1"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtClose, status:0x0, handle:0x5
C8
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtEnumerateKey, status:0x0, ind

ex:0x2, class:0x0, length:0x120, resultlength:0x44, handle:0x564, path:"\REGISTR


Y\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDl
lDecodeObjectEx"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x5C8, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\C
ryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.11
"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtQueryKey, status:0x0, class:0
x4, length:0xB0, resultlength:0x28, handle:0x5C8, path:"\REGISTRY\MACHINE\SOFTWA
RE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\
1.2.840.113549.1.9.16.2.11"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtEnumerateValueKey, status:0x0
, index:0x0, class:0x1, length:0xDC, resultlength:0x62, handle:0x5C8, path:"\REG
ISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\Cry
ptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.11"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtEnumerateValueKey, status:0x0
, index:0x1, class:0x1, length:0xDC, resultlength:0x62, handle:0x5C8, path:"\REG
ISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\Cry
ptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.11"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtClose, status:0x0, handle:0x5
C8
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x3, class:0x0, length:0x120, resultlength:0x44, handle:0x564, path:"\REGISTR
Y\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDl
lDecodeObjectEx"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x5C8, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\C
ryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.12
"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtQueryKey, status:0x0, class:0
x4, length:0xB0, resultlength:0x28, handle:0x5C8, path:"\REGISTRY\MACHINE\SOFTWA
RE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\
1.2.840.113549.1.9.16.2.12"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtEnumerateValueKey, status:0x0
, index:0x0, class:0x1, length:0xDC, resultlength:0x62, handle:0x5C8, path:"\REG
ISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\Cry
ptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.12"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtEnumerateValueKey, status:0x0
, index:0x1, class:0x1, length:0xDC, resultlength:0x5E, handle:0x5C8, path:"\REG
ISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\Cry
ptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.12"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtClose, status:0x0, handle:0x5
C8
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x4, class:0x0, length:0x120, resultlength:0x42, handle:0x564, path:"\REGISTR
Y\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDl
lDecodeObjectEx"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x5C8, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\C
ryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.2"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtQueryKey, status:0x0, class:0
x4, length:0xB0, resultlength:0x28, handle:0x5C8, path:"\REGISTRY\MACHINE\SOFTWA
RE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\
1.2.840.113549.1.9.16.2.2"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtEnumerateValueKey, status:0x0
, index:0x0, class:0x1, length:0xDC, resultlength:0x62, handle:0x5C8, path:"\REG
ISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\Cry
ptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.2"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtEnumerateValueKey, status:0x0
, index:0x1, class:0x1, length:0xDC, resultlength:0x5A, handle:0x5C8, path:"\REG

ISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\Cry
ptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.2"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtClose, status:0x0, handle:0x5
C8
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x5, class:0x0, length:0x120, resultlength:0x42, handle:0x564, path:"\REGISTR
Y\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDl
lDecodeObjectEx"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x5C8, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\C
ryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.3"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtQueryKey, status:0x0, class:0
x4, length:0xB0, resultlength:0x28, handle:0x5C8, path:"\REGISTRY\MACHINE\SOFTWA
RE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\
1.2.840.113549.1.9.16.2.3"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtEnumerateValueKey, status:0x0
, index:0x0, class:0x1, length:0xDC, resultlength:0x62, handle:0x5C8, path:"\REG
ISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\Cry
ptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.3"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtEnumerateValueKey, status:0x0
, index:0x1, class:0x1, length:0xDC, resultlength:0x52, handle:0x5C8, path:"\REG
ISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\Cry
ptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.3"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtClose, status:0x0, handle:0x5
C8
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x6, class:0x0, length:0x120, resultlength:0x42, handle:0x564, path:"\REGISTR
Y\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDl
lDecodeObjectEx"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x5C8, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\C
ryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.4"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtQueryKey, status:0x0, class:0
x4, length:0xB0, resultlength:0x28, handle:0x5C8, path:"\REGISTRY\MACHINE\SOFTWA
RE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\
1.2.840.113549.1.9.16.2.4"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtEnumerateValueKey, status:0x0
, index:0x0, class:0x1, length:0xDC, resultlength:0x62, handle:0x5C8, path:"\REG
ISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\Cry
ptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.4"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtEnumerateValueKey, status:0x0
, index:0x1, class:0x1, length:0xDC, resultlength:0x56, handle:0x5C8, path:"\REG
ISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\Cry
ptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.4"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtClose, status:0x0, handle:0x5
C8
pid:4092, tid:1488, tick:0x33D7280, lvl:LOG, func:NtEnumerateKey, status:0x80000
01A, index:0x7, class:0x0, length:0x120, resultlength:0x0, handle:0x564, path:"\
REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\
CryptDllDecodeObjectEx"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtClose, status:0x0, handle:0x5
64
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtClose, status:0x0, handle:0x5
74
pid:4092, tid:1488, tick:0x33D7280, lvl:LOG, func:NtEnumerateKey, status:0x80000
01A, index:0x2, class:0x0, length:0x120, resultlength:0x0, handle:0x538, path:"\
REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtClose, status:0x0, handle:0x5
38
pid:4092, tid:8264, tick:0x33D7280, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034

, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows


NT\CurrentVersion\msasn1"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtClose, status:0x0, handle:0x5
A8
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtClose, status:0x0, handle:0x6
48
pid:4092, tid:1488, tick:0x33D7280, lvl:LOG, func:NtOpenSection, status:0xC00000
34, handle:0x0, access:0xF, path:"\KnownDlls32\DPAPI.DLL"
pid:4092, tid:1488, tick:0x33D7280, lvl:LOG, func:NtQueryAttributesFile, status:
0xC0000034, path:"C:\Users\i92segoa\Desktop\Firefox SEO\DPAPI.DLL"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x20, path:"C:\WINDOWS\SYSTEM32\DPAPI.DLL"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtOpenFile, status:0x0, handle:
0x674, access:0x100021, iostatus:0x0, information:0x1, share:0x5, options:0x60,
path:"C:\WINDOWS\SYSTEM32\DPAPI.DLL"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtCreateSection, status:0x0, ha
ndle:0x678, access:0xF, pageattribs:0x10, sectionattribs:0x1000000, file:0x674
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x701B0000, zerobits:0x0, commitsize:0x0, viewsize:0x8000, disposition:
0x1, type:0x800000, protect:0x4, handle:0x678, path:"C:\WINDOWS\SYSTEM32\DPAPI.D
LL"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtClose, status:0x0, handle:0x6
78
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtClose, status:0x0, handle:0x6
74
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x701C0000
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x701C0000
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtOpenSection, status:0x0, hand
le:0x648, access:0xF, path:"\KnownDlls32\WINTRUST.dll"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x74960000, zerobits:0x0, commitsize:0x0, viewsize:0x42000, disposition
:0x1, type:0x800000, protect:0x4, handle:0x648, path:"\KnownDlls32\WINTRUST.dll"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtClose, status:0x0, handle:0x6
48
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtCreateMutant, status:0x0, han
dle:0x5CC, access:0x1F0001, owner:0x0
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtCreateMutant, status:0x0, han
dle:0x5E8, access:0x1F0001, owner:0x0
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x701C0000
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x701C0000
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x5A8, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptography\
Providers\Trust\Certificate\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"$DLL", class:0x2, length:0x90, resultlength:0x4E, handle:0x5A8, path:"\REGIS
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Certific
ate\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}"
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x674, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptography\
Providers\Trust\Certificate\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"$Function", class:0x2, length:0x90, resultlength:0x38, handle:0x5A8, path:"\
REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Cer
tificate\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}"
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"$DLL", class:0x2, length:0x90, resultlength:0x4E, handle:0x674, path:"\REGIS

TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Certific
ate\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtClose, status:0x0, handle:0x5
A8
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"$Function", class:0x2, length:0x90, resultlength:0x38, handle:0x674, path:"\
REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Cer
tificate\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}"
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtClose, status:0x0, handle:0x6
74
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x5A8, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptography\
Providers\Trust\FinalPolicy\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"$DLL", class:0x2, length:0x90, resultlength:0x4E, handle:0x5A8, path:"\REGIS
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\FinalPol
icy\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}"
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x674, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptography\
Providers\Trust\FinalPolicy\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"$Function", class:0x2, length:0x90, resultlength:0x2A, handle:0x5A8, path:"\
REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Fin
alPolicy\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtClose, status:0x0, handle:0x5
A8
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"$DLL", class:0x2, length:0x90, resultlength:0x4E, handle:0x674, path:"\REGIS
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\FinalPol
icy\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}"
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"$Function", class:0x2, length:0x90, resultlength:0x2A, handle:0x674, path:"\
REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Fin
alPolicy\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x5A8, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptography\
Providers\Trust\Initialization\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"$DLL", class:0x2, length:0x90, resultlength:0x4E, handle:0x5A8, path:"\REGIS
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Initiali
zation\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}"
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtClose, status:0x0, handle:0x6
74
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"$Function", class:0x2, length:0x90, resultlength:0x30, handle:0x5A8, path:"\
REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Ini
tialization\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtClose, status:0x0, handle:0x5
A8
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x538, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptography\
Providers\Trust\Initialization\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x674, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptography\
Providers\Trust\Message\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}"
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"$DLL", class:0x2, length:0x90, resultlength:0x4E, handle:0x538, path:"\REGIS
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Initiali
zation\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtQueryValueKey, status:0x0, na

me:"$DLL", class:0x2, length:0x90, resultlength:0x4E, handle:0x674, path:"\REGIS


TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Message\
{573E31F8-AABA-11D0-8CCB-00C04FC295EE}"
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"$Function", class:0x2, length:0x90, resultlength:0x30, handle:0x538, path:"\
REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Ini
tialization\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"$Function", class:0x2, length:0x90, resultlength:0x32, handle:0x674, path:"\
REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Mes
sage\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtClose, status:0x0, handle:0x6
74
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtClose, status:0x0, handle:0x5
38
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x674, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptography\
Providers\Trust\Signature\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}"
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x538, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptography\
Providers\Trust\Message\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"$DLL", class:0x2, length:0x90, resultlength:0x4E, handle:0x674, path:"\REGIS
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Signatur
e\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"$Function", class:0x2, length:0x90, resultlength:0x36, handle:0x674, path:"\
REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Sig
nature\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}"
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"$DLL", class:0x2, length:0x90, resultlength:0x4E, handle:0x538, path:"\REGIS
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Message\
{573E31F8-AABA-11D0-8CCB-00C04FC295EE}"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtClose, status:0x0, handle:0x6
74
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"$Function", class:0x2, length:0x90, resultlength:0x32, handle:0x538, path:"\
REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Mes
sage\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}"
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtClose, status:0x0, handle:0x5
38
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x674, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptography\
Providers\Trust\CertCheck\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"$DLL", class:0x2, length:0x90, resultlength:0x4E, handle:0x674, path:"\REGIS
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\CertChec
k\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}"
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x574, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptography\
Providers\Trust\Signature\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"$Function", class:0x2, length:0x90, resultlength:0x2E, handle:0x674, path:"\
REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Cer
tCheck\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}"
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"$DLL", class:0x2, length:0x90, resultlength:0x4E, handle:0x574, path:"\REGIS
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Signatur
e\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtClose, status:0x0, handle:0x6

74
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"$Function", class:0x2, length:0x90, resultlength:0x36, handle:0x574, path:"\
REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Sig
nature\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}"
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtClose, status:0x0, handle:0x5
74
pid:4092, tid:1488, tick:0x33D7280, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptog
raphy\Providers\Trust\DiagnosticPolicy\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}"
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x660, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptography\
Providers\Trust\CertCheck\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x574, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptography\
Providers\Trust\Cleanup\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}"
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"$DLL", class:0x2, length:0x90, resultlength:0x4E, handle:0x660, path:"\REGIS
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\CertChec
k\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"$DLL", class:0x2, length:0x90, resultlength:0x4E, handle:0x574, path:"\REGIS
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Cleanup\
{573E31F8-AABA-11D0-8CCB-00C04FC295EE}"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"$Function", class:0x2, length:0x90, resultlength:0x2A, handle:0x574, path:"\
REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Cle
anup\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtClose, status:0x0, handle:0x5
74
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"$Function", class:0x2, length:0x90, resultlength:0x2E, handle:0x660, path:"\
REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Cer
tCheck\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtWaitForMultipleObjects, statu
s:0x0, count:0x2, type:0x0, alertable:0x0, objects:0x5CC;0x5E4
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtClose, status:0x0, handle:0x6
60
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"C:\Windows\SysWOW64\WINTRUST.DLL", handle:0x74960000
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"C:\Windows\SysWOW64\WINTRUST.DLL", handle:0x74960000
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"C:\Windows\SysWOW64\WINTRUST.DLL", handle:0x74960000
pid:4092, tid:8264, tick:0x33D7280, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptog
raphy\Providers\Trust\DiagnosticPolicy\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"C:\Windows\SysWOW64\WINTRUST.DLL", handle:0x74960000
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"C:\Windows\SysWOW64\WINTRUST.DLL", handle:0x74960000
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"C:\Windows\SysWOW64\WINTRUST.DLL", handle:0x74960000
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"C:\Windows\SysWOW64\WINTRUST.DLL", handle:0x74960000
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x574, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptography\
Providers\Trust\Cleanup\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74960000, name:"HTTPSCertificateTrust", ordinal:0x0, addr

ess:0x7496CC30, image:0x0, caller:0x7496C116


pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74960000, name:"HTTPSFinalProv", ordinal:0x0, address:0x7
4970AD0, image:0x0, caller:0x7496C155
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"$DLL", class:0x2, length:0x90, resultlength:0x4E, handle:0x574, path:"\REGIS
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Cleanup\
{573E31F8-AABA-11D0-8CCB-00C04FC295EE}"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74960000, name:"SoftpubInitialize", ordinal:0x0, address:
0x7496F0B0, image:0x0, caller:0x7496C194
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74960000, name:"SoftpubLoadMessage", ordinal:0x0, address
:0x7496E7D0, image:0x0, caller:0x7496C1CB
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"$Function", class:0x2, length:0x90, resultlength:0x2A, handle:0x574, path:"\
REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Cle
anup\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74960000, name:"SoftpubLoadSignature", ordinal:0x0, addre
ss:0x7496E510, image:0x0, caller:0x7496C1F3
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtClose, status:0x0, handle:0x5
74
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74960000, name:"SoftpubCheckCert", ordinal:0x0, address:0
x74976500, image:0x0, caller:0x7496C21B
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74960000, name:"SoftpubCleanup", ordinal:0x0, address:0x7
496F0A0, image:0x0, caller:0x7496C254
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtWaitForMultipleObjects, statu
s:0x0, count:0x2, type:0x0, alertable:0x0, objects:0x5CC;0x5E4
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x74960000
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"C:\Windows\SysWOW64\WINTRUST.DLL", handle:0x74960000
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"C:\Windows\SysWOW64\WINTRUST.DLL", handle:0x74960000
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"C:\Windows\SysWOW64\WINTRUST.DLL", handle:0x74960000
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"C:\Windows\SysWOW64\WINTRUST.DLL", handle:0x74960000
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"C:\Windows\SysWOW64\WINTRUST.DLL", handle:0x74960000
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x674, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\Microsoft\Cryptography\
Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider"
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"C:\Windows\SysWOW64\WINTRUST.DLL", handle:0x74960000
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"C:\Windows\SysWOW64\WINTRUST.DLL", handle:0x74960000
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Type", class:0x2, length:0x90, resultlength:0x10, handle:0x674, path:"\REGIS
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Micros
oft Enhanced RSA and AES Cryptographic Provider"
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74960000, name:"HTTPSCertificateTrust", ordinal:0x0, addr
ess:0x7496CC30, image:0x0, caller:0x7496C116
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74960000, name:"HTTPSFinalProv", ordinal:0x0, address:0x7
4970AD0, image:0x0, caller:0x7496C155

pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtQueryValueKey, status:0x0, na


me:"Image Path", class:0x2, length:0x90, resultlength:0x4E, handle:0x674, path:"
\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\
Microsoft Enhanced RSA and AES Cryptographic Provider"
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74960000, name:"SoftpubInitialize", ordinal:0x0, address:
0x7496F0B0, image:0x0, caller:0x7496C194
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74960000, name:"SoftpubLoadMessage", ordinal:0x0, address
:0x7496E7D0, image:0x0, caller:0x7496C1CB
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Image Path", class:0x2, length:0x90, resultlength:0x4E, handle:0x674, path:"
\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\
Microsoft Enhanced RSA and AES Cryptographic Provider"
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74960000, name:"SoftpubLoadSignature", ordinal:0x0, addre
ss:0x7496E510, image:0x0, caller:0x7496C1F3
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74960000, name:"SoftpubCheckCert", ordinal:0x0, address:0
x74976500, image:0x0, caller:0x7496C21B
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Image Path", class:0x2, length:0x90, resultlength:0x4E, handle:0x674, path:"
\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\
Microsoft Enhanced RSA and AES Cryptographic Provider"
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74960000, name:"SoftpubCleanup", ordinal:0x0, address:0x7
496F0A0, image:0x0, caller:0x7496C254
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Image Path", class:0x2, length:0x90, resultlength:0x4E, handle:0x674, path:"
\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\
Microsoft Enhanced RSA and AES Cryptographic Provider"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"C:\WINDOWS\system32\rsaenh.dll", handle:0x705E0000
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPAcquireContext", ordinal:0x0, address:0
x705E4CA0, image:0x0, caller:0x706542D4
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPReleaseContext", ordinal:0x0, address:0
x705E8930, image:0x0, caller:0x706542D4
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x664, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\Microsoft\Cryptography\
Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPGenKey", ordinal:0x0, address:0x705E600
0, image:0x0, caller:0x706542D4
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPDeriveKey", ordinal:0x0, address:0x705F
ADE0, image:0x0, caller:0x706542D4
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPDestroyKey", ordinal:0x0, address:0x705
E6D30, image:0x0, caller:0x706542D4
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Type", class:0x2, length:0x90, resultlength:0x10, handle:0x664, path:"\REGIS
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Micros
oft Enhanced RSA and AES Cryptographic Provider"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPSetKeyParam", ordinal:0x0, address:0x70
5FC7D0, image:0x0, caller:0x706542D4
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPGetKeyParam", ordinal:0x0, address:0x70

5E8800, image:0x0, caller:0x706542D4


pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPExportKey", ordinal:0x0, address:0x705E
5B80, image:0x0, caller:0x706542D4
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Image Path", class:0x2, length:0x90, resultlength:0x4E, handle:0x664, path:"
\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\
Microsoft Enhanced RSA and AES Cryptographic Provider"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPImportKey", ordinal:0x0, address:0x705E
7440, image:0x0, caller:0x706542D4
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPEncrypt", ordinal:0x0, address:0x705F98
E0, image:0x0, caller:0x706542D4
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Image Path", class:0x2, length:0x90, resultlength:0x4E, handle:0x664, path:"
\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\
Microsoft Enhanced RSA and AES Cryptographic Provider"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPDecrypt", ordinal:0x0, address:0x705E95
A0, image:0x0, caller:0x706542D4
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPCreateHash", ordinal:0x0, address:0x705
E8040, image:0x0, caller:0x706542D4
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Image Path", class:0x2, length:0x90, resultlength:0x4E, handle:0x664, path:"
\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\
Microsoft Enhanced RSA and AES Cryptographic Provider"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPHashData", ordinal:0x0, address:0x705E6
A30, image:0x0, caller:0x706542D4
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPHashSessionKey", ordinal:0x0, address:0
x705FA650, image:0x0, caller:0x706542D4
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Image Path", class:0x2, length:0x90, resultlength:0x4E, handle:0x664, path:"
\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\
Microsoft Enhanced RSA and AES Cryptographic Provider"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPDestroyHash", ordinal:0x0, address:0x70
5E5A30, image:0x0, caller:0x706542D4
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPSignHash", ordinal:0x0, address:0x705FF
0B0, image:0x0, caller:0x706542D4
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"C:\WINDOWS\system32\rsaenh.dll", handle:0x705E0000
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPVerifySignature", ordinal:0x0, address:
0x705E6290, image:0x0, caller:0x706542D4
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPGenRandom", ordinal:0x0, address:0x705E
8C10, image:0x0, caller:0x706542D4
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPAcquireContext", ordinal:0x0, address:0
x705E4CA0, image:0x0, caller:0x706542D4
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPGetUserKey", ordinal:0x0, address:0x705
EB040, image:0x0, caller:0x706542D4
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPReleaseContext", ordinal:0x0, address:0

x705E8930, image:0x0, caller:0x706542D4


pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPSetProvParam", ordinal:0x0, address:0x7
05FD280, image:0x0, caller:0x706542D4
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPGenKey", ordinal:0x0, address:0x705E600
0, image:0x0, caller:0x706542D4
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPGetProvParam", ordinal:0x0, address:0x7
05FB820, image:0x0, caller:0x706542D4
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPDeriveKey", ordinal:0x0, address:0x705F
ADE0, image:0x0, caller:0x706542D4
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPSetHashParam", ordinal:0x0, address:0x7
05E6EC0, image:0x0, caller:0x706542D4
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPDestroyKey", ordinal:0x0, address:0x705
E6D30, image:0x0, caller:0x706542D4
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPGetHashParam", ordinal:0x0, address:0x7
05E6550, image:0x0, caller:0x706542D4
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPSetKeyParam", ordinal:0x0, address:0x70
5FC7D0, image:0x0, caller:0x706542D4
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPDuplicateKey", ordinal:0x0, address:0x7
05FB620, image:0x0, caller:0x70654303
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPGetKeyParam", ordinal:0x0, address:0x70
5E8800, image:0x0, caller:0x706542D4
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPDuplicateHash", ordinal:0x0, address:0x
705FA4C0, image:0x0, caller:0x70654303
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPExportKey", ordinal:0x0, address:0x705E
5B80, image:0x0, caller:0x706542D4
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPImportKey", ordinal:0x0, address:0x705E
7440, image:0x0, caller:0x706542D4
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x66C, c
lass:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPEncrypt", ordinal:0x0, address:0x705F98
E0, image:0x0, caller:0x706542D4
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPDecrypt", ordinal:0x0, address:0x705E95
A0, image:0x0, caller:0x706542D4
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtClose, status:0x0, handle:0x6
6C
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPCreateHash", ordinal:0x0, address:0x705
E8040, image:0x0, caller:0x706542D4
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPHashData", ordinal:0x0, address:0x705E6
A30, image:0x0, caller:0x706542D4
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPHashSessionKey", ordinal:0x0, address:0
x705FA650, image:0x0, caller:0x706542D4

pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtOpenKeyEx, status:0x0, handle


:0x5A8, access:0x20119, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptography"
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPDestroyHash", ordinal:0x0, address:0x70
5E5A30, image:0x0, caller:0x706542D4
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPSignHash", ordinal:0x0, address:0x705FF
0B0, image:0x0, caller:0x706542D4
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"MachineGuid", class:0x2, length:0x90, resultlength:0x56, handle:0x5A8, path:
"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Cryptography"
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPVerifySignature", ordinal:0x0, address:
0x705E6290, image:0x0, caller:0x706542D4
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"MachineGuid", class:0x2, length:0x90, resultlength:0x56, handle:0x5A8, path:
"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Cryptography"
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPGenRandom", ordinal:0x0, address:0x705E
8C10, image:0x0, caller:0x706542D4
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"MachineGuid", class:0x2, length:0x90, resultlength:0x56, handle:0x5A8, path:
"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Cryptography"
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPGetUserKey", ordinal:0x0, address:0x705
EB040, image:0x0, caller:0x706542D4
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"MachineGuid", class:0x2, length:0x90, resultlength:0x56, handle:0x5A8, path:
"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Cryptography"
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPSetProvParam", ordinal:0x0, address:0x7
05FD280, image:0x0, caller:0x706542D4
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtClose, status:0x0, handle:0x5
A8
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPGetProvParam", ordinal:0x0, address:0x7
05FB820, image:0x0, caller:0x706542D4
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPSetHashParam", ordinal:0x0, address:0x7
05E6EC0, image:0x0, caller:0x706542D4
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPGetHashParam", ordinal:0x0, address:0x7
05E6550, image:0x0, caller:0x706542D4
pid:4092, tid:1488, tick:0x33D7280, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptog
raphy\Offload"
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPDuplicateKey", ordinal:0x0, address:0x7
05FB620, image:0x0, caller:0x70654303
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x5A8, c
lass:0x1, length:0x400, returnlength:0x24, sid:"S-1-5-21-2360094602-2602383397-2
463990887-1001", attributes:0x0
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPDuplicateHash", ordinal:0x0, address:0x
705FA4C0, image:0x0, caller:0x70654303
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtClose, status:0x0, handle:0x5
A8
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x66C, c

lass:0x1D, length:0x4, returnlength:0x4


pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtClose, status:0x0, handle:0x6
6C
pid:4092, tid:1488, tick:0x33D7280, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptog
raphy\DESHashSessionKeyBackward"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtClose, status:0x0, handle:0x6
74
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x66C, access:0x20119, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptography"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x674, c
lass:0x1, length:0x100, returnlength:0x24, sid:"S-1-5-21-2360094602-2602383397-2
463990887-1001", attributes:0x0
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtClose, status:0x0, handle:0x6
74
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"MachineGuid", class:0x2, length:0x90, resultlength:0x56, handle:0x66C, path:
"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Cryptography"
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"MachineGuid", class:0x2, length:0x90, resultlength:0x56, handle:0x66C, path:
"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Cryptography"
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"MachineGuid", class:0x2, length:0x90, resultlength:0x56, handle:0x66C, path:
"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Cryptography"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x5A8, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001"
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"MachineGuid", class:0x2, length:0x90, resultlength:0x56, handle:0x66C, path:
"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Cryptography"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtCreateKey, status:0x0, handle
:0x668, access:0x20019, title:0x0, class:"", options:0x0, disposition:0x2, path:
"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\Software\Microsof
t\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing"
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtClose, status:0x0, handle:0x6
6C
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtClose, status:0x0, handle:0x5
A8
pid:4092, tid:8264, tick:0x33D7280, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptog
raphy\Offload"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"State", class:0x2, length:0x90, resultlength:0x10, handle:0x668, path:"\REGI
STRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Wind
ows\CurrentVersion\WinTrust\Trust Providers\Software Publishing"
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x5F4, c
lass:0x1, length:0x400, returnlength:0x24, sid:"S-1-5-21-2360094602-2602383397-2
463990887-1001", attributes:0x0
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtClose, status:0x0, handle:0x6
68
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtClose, status:0x0, handle:0x5
F4
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x5F4, c
lass:0x1, length:0x100, returnlength:0x24, sid:"S-1-5-21-2360094602-2602383397-2
463990887-1001", attributes:0x0
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtClose, status:0x0, handle:0x5
F4

pid:4092, tid:8264, tick:0x33D7280, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034


, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptog
raphy\DESHashSessionKeyBackward"
pid:4092, tid:8264, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
64
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x668, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001"
pid:4092, tid:8264, tick:0x33D728F, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x664, c
lass:0x1, length:0x100, returnlength:0x24, sid:"S-1-5-21-2360094602-2602383397-2
463990887-1001", attributes:0x0
pid:4092, tid:8264, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
64
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x670, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Internet Explorer\Security"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
68
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Safety Warning Level", class:0x2, length:0x90, resultlength:0x18, handle:0x6
70, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE
\Microsoft\Internet Explorer\Security"
pid:4092, tid:8264, tick:0x33D728F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x5F4, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
70
pid:4092, tid:1488, tick:0x33D728F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies\Microsof
t\SystemCertificates\TrustedPublisher\Safer"
pid:4092, tid:8264, tick:0x33D728F, lvl:OK, func:NtCreateKey, status:0x0, handle
:0x668, access:0x20019, title:0x0, class:"", options:0x0, disposition:0x2, path:
"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\Software\Microsof
t\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x66C, c
lass:0x1, length:0x100, returnlength:0x24, sid:"S-1-5-21-2360094602-2602383397-2
463990887-1001", attributes:0x0
pid:4092, tid:8264, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x5
F4
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
6C
pid:4092, tid:8264, tick:0x33D728F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"State", class:0x2, length:0x90, resultlength:0x10, handle:0x668, path:"\REGI
STRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Wind
ows\CurrentVersion\WinTrust\Trust Providers\Software Publishing"
pid:4092, tid:8264, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
68
pid:4092, tid:8264, tick:0x33D728F, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x668, c
lass:0x1, length:0x100, returnlength:0x24, sid:"S-1-5-21-2360094602-2602383397-2
463990887-1001", attributes:0x0
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x574, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001"
pid:4092, tid:8264, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
68
pid:4092, tid:1488, tick:0x33D728F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339

7-2463990887-1001\Software\Policies\Microsoft\SystemCertificates\TrustedPublishe
r\Safer"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x5
74
pid:4092, tid:1488, tick:0x33D728F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\SystemC
ertificates\TrustedPublisher\Safer"
pid:4092, tid:8264, tick:0x33D728F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x538, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x574, access:0x20019, path:"\REGISTRY\MACHINE\SYSTEM\CurrentControlSet\Service
s\crypt32"
pid:4092, tid:1488, tick:0x33D728F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DiagLevel", class:0x2, length:0x90, resultlength:0x0, handle:0x574,
path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\crypt32"
pid:4092, tid:1488, tick:0x33D728F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DiagMatchAnyMask", class:0x2, length:0x90, resultlength:0x0, handle:
0x574, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\crypt32"
pid:4092, tid:8264, tick:0x33D728F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x67C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Internet Explorer\Security"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x5
74
pid:4092, tid:8264, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x5
38
pid:4092, tid:8264, tick:0x33D728F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Safety Warning Level", class:0x2, length:0x90, resultlength:0x18, handle:0x6
7C, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE
\Microsoft\Internet Explorer\Security"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x574, access:0x20019, path:"\REGISTRY\MACHINE\SYSTEM\CurrentControlSet\Service
s\crypt32"
pid:4092, tid:8264, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
7C
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtNotifyChangeKey, status:0x103
, event:0x678, iostatus:0x103, information:0x0, filter:0x10000004, watch:0x0, le
ngth:0x0, async:0x1, handle:0x574, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\
Services\crypt32"
pid:4092, tid:8264, tick:0x33D728F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies\Microsof
t\SystemCertificates\TrustedPublisher\Safer"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x684, iocompletion:0x660, handle:0x680
pid:4092, tid:8264, tick:0x33D728F, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x688, c
lass:0x1, length:0x100, returnlength:0x24, sid:"S-1-5-21-2360094602-2602383397-2
463990887-1001", attributes:0x0
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x690, iocompletion:0x660, handle:0x68C
pid:4092, tid:8264, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
88
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x67C, iocompletion:0x660, handle:0x678
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
88
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
94
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x694, c

lass:0x1D, length:0x4, returnlength:0x4


pid:4092, tid:8264, tick:0x33D728F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x69C, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
94
pid:4092, tid:8264, tick:0x33D728F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001\Software\Policies\Microsoft\SystemCertificates\TrustedPublishe
r\Safer"
pid:4092, tid:8264, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
9C
pid:4092, tid:8264, tick:0x33D728F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\SystemC
ertificates\TrustedPublisher\Safer"
pid:4092, tid:8264, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
9C
pid:4092, tid:8264, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
98
pid:4092, tid:8264, tick:0x33D728F, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x698, c
lass:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x6A0, access:0x20119, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptography\
OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config"
pid:4092, tid:8264, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
98
pid:4092, tid:1488, tick:0x33D728F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DisableSerialChain", class:0x2, length:0x90, resultlength:0x80000002
, handle:0x6A0, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Cryptography\OID\Enco
dingType 0\CertDllCreateCertificateChainEngine\Config"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
A0
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x6A0, access:0x20119, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptography\
OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config"
pid:4092, tid:1488, tick:0x33D728F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"CryptnetPreFetchTriggerPeriodSeconds", class:0x2, length:0x90, resul
tlength:0x331F4D0, handle:0x6A0, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Cryp
tography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config"
pid:4092, tid:1488, tick:0x33D728F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"MaxUrlRetrievalByteCount", class:0x2, length:0x90, resultlength:0x33
1F4D0, handle:0x6A0, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Cryptography\OID
\EncodingType 0\CertDllCreateCertificateChainEngine\Config"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x698, access:0x20119, path:"\REGISTRY\MACHINE\Software\Microsoft\SystemCertifi
cates\AuthRoot\AutoUpdate"
pid:4092, tid:1488, tick:0x33D728F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DisallowedCertSyncDeltaTime", class:0x2, length:0x90, resultlength:0
x77793E5E, handle:0x698, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\SystemCertif
icates\AuthRoot\AutoUpdate"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
98
pid:4092, tid:1488, tick:0x33D728F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\SystemC
ertificates\Root\PhysicalStores"
pid:4092, tid:1488, tick:0x33D728F, lvl:LOG, func:NtCreateKey, status:0xC0000022
, handle:0x0, access:0x3001F, title:0x0, class:"", options:0x0, disposition:0xFF
FF0000, path:"\REGISTRY\MACHINE\Software\Microsoft\SystemCertificates\Root"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtCreateKey, status:0x0, handle

:0x6A4, access:0x2000000, title:0x0, class:"", options:0x0, disposition:0x2, pat


h:"\REGISTRY\MACHINE\Software"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5A0000, zerobits:0x0, commitsize:0x0, offset:0x220000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x3760000
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x670000, zerobits:0x0, commitsize:0x0, offset:0x270000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5A0000
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtCreateKey, status:0x0, handle
:0x6A8, access:0x2000000, title:0x0, class:"", options:0x0, disposition:0x2, pat
h:"\REGISTRY\MACHINE\Software\Microsoft"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
A4
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtCreateKey, status:0x0, handle
:0x6A4, access:0x2000000, title:0x0, class:"", options:0x0, disposition:0x2, pat
h:"\REGISTRY\MACHINE\Software\Microsoft\SystemCertificates"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
A8
pid:4092, tid:8684, tick:0x33D728F, lvl:LOG, func:BaseThreadInitThunk, log:"New
thread started (via BaseThreadInitThunk) at address: 0x77C3C6D0, parameter: 0x7F
5938"
pid:4092, tid:1488, tick:0x33D728F, lvl:LOG, func:NtCreateKey, status:0xC0000022
, handle:0x0, access:0x3001F, title:0x0, class:"", options:0x0, disposition:0x2,
path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\SystemCertificates\Root"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
A4
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x668, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\SystemCertifi
cates\Root"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
68
pid:4092, tid:1488, tick:0x33D728F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies\Microsof
t\SystemCertificates\Root\ProtectedRoots"
pid:4092, tid:1488, tick:0x33D728F, lvl:LOG, func:NtCreateKey, status:0xC0000022
, handle:0x0, access:0x3001F, title:0x0, class:"", options:0x0, disposition:0x40
, path:"\REGISTRY\MACHINE\Software\Microsoft\SystemCertificates\Root"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtCreateKey, status:0x0, handle
:0x6AC, access:0x2000000, title:0x0, class:"", options:0x0, disposition:0x2, pat
h:"\REGISTRY\MACHINE\Software"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtCreateKey, status:0x0, handle
:0x668, access:0x2000000, title:0x0, class:"", options:0x0, disposition:0x2, pat
h:"\REGISTRY\MACHINE\Software\Microsoft"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
AC
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtCreateKey, status:0x0, handle
:0x6AC, access:0x2000000, title:0x0, class:"", options:0x0, disposition:0x2, pat
h:"\REGISTRY\MACHINE\Software\Microsoft\SystemCertificates"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
68
pid:4092, tid:1488, tick:0x33D728F, lvl:LOG, func:NtCreateKey, status:0xC0000022
, handle:0x0, access:0x3001F, title:0x0, class:"", options:0x0, disposition:0x2,
path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\SystemCertificates\Root"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
AC
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle

:0x6AC, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\SystemCertifi


cates\Root"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x6A4, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\SystemCertifi
cates\ROOT\"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
AC
pid:4092, tid:1488, tick:0x33D728F, lvl:LOG, func:NtCreateKey, status:0xC0000022
, handle:0x0, access:0x3001F, title:0x0, class:"", options:0x0, disposition:0x0,
path:"\REGISTRY\MACHINE\Software\Microsoft\SystemCertificates\AuthRoot"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtCreateKey, status:0x0, handle
:0x6AC, access:0x2000000, title:0x0, class:"", options:0x0, disposition:0x2, pat
h:"\REGISTRY\MACHINE\Software"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtCreateKey, status:0x0, handle
:0x6A8, access:0x2000000, title:0x0, class:"", options:0x0, disposition:0x2, pat
h:"\REGISTRY\MACHINE\Software\Microsoft"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
AC
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtCreateKey, status:0x0, handle
:0x6AC, access:0x2000000, title:0x0, class:"", options:0x0, disposition:0x2, pat
h:"\REGISTRY\MACHINE\Software\Microsoft\SystemCertificates"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
A8
pid:4092, tid:1488, tick:0x33D728F, lvl:LOG, func:NtCreateKey, status:0xC0000022
, handle:0x0, access:0x3001F, title:0x0, class:"", options:0x0, disposition:0x2,
path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\SystemCertificates\AuthRoot"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
AC
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x6AC, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\SystemCertifi
cates\AuthRoot"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x6A8, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\SystemCertifi
cates\AuthRoot\"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
AC
pid:4092, tid:1488, tick:0x33D728F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Enterpr
iseCertificates\Root\PhysicalStores"
pid:4092, tid:1488, tick:0x33D728F, lvl:LOG, func:NtCreateKey, status:0xC0000022
, handle:0x0, access:0x3001F, title:0x0, class:"", options:0x0, disposition:0xFF
FFFFFE, path:"\REGISTRY\MACHINE\Software\Microsoft\EnterpriseCertificates\Root"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtCreateKey, status:0x0, handle
:0x6B0, access:0x2000000, title:0x0, class:"", options:0x0, disposition:0x2, pat
h:"\REGISTRY\MACHINE\Software"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtCreateKey, status:0x0, handle
:0x6AC, access:0x2000000, title:0x0, class:"", options:0x0, disposition:0x2, pat
h:"\REGISTRY\MACHINE\Software\Microsoft"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
B0
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtCreateKey, status:0x0, handle
:0x6B0, access:0x2000000, title:0x0, class:"", options:0x0, disposition:0x2, pat
h:"\REGISTRY\MACHINE\Software\Microsoft\EnterpriseCertificates"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
AC
pid:4092, tid:1488, tick:0x33D728F, lvl:LOG, func:NtCreateKey, status:0xC0000022
, handle:0x0, access:0x3001F, title:0x0, class:"", options:0x0, disposition:0x2,
path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\EnterpriseCertificates\Root"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
B0

pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle


:0x6B0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\EnterpriseCer
tificates\Root"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
B0
pid:4092, tid:1488, tick:0x33D728F, lvl:LOG, func:NtCreateKey, status:0xC0000022
, handle:0x0, access:0x3001F, title:0x0, class:"", options:0x0, disposition:0x1,
path:"\REGISTRY\MACHINE\Software\Microsoft\EnterpriseCertificates\Root"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtCreateKey, status:0x0, handle
:0x6B0, access:0x2000000, title:0x0, class:"", options:0x0, disposition:0x2, pat
h:"\REGISTRY\MACHINE\Software"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtCreateKey, status:0x0, handle
:0x6AC, access:0x2000000, title:0x0, class:"", options:0x0, disposition:0x2, pat
h:"\REGISTRY\MACHINE\Software\Microsoft"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
B0
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtCreateKey, status:0x0, handle
:0x6B0, access:0x2000000, title:0x0, class:"", options:0x0, disposition:0x2, pat
h:"\REGISTRY\MACHINE\Software\Microsoft\EnterpriseCertificates"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
AC
pid:4092, tid:1488, tick:0x33D728F, lvl:LOG, func:NtCreateKey, status:0xC0000022
, handle:0x0, access:0x3001F, title:0x0, class:"", options:0x0, disposition:0x2,
path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\EnterpriseCertificates\Root"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
B0
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x6B0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\EnterpriseCer
tificates\Root"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x6AC, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\EnterpriseCer
tificates\Root\"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
B0
pid:4092, tid:1488, tick:0x33D728F, lvl:LOG, func:NtCreateKey, status:0xC0000022
, handle:0x0, access:0x3001F, title:0x0, class:"", options:0x0, disposition:0x54
, path:"\REGISTRY\MACHINE\Software\Microsoft\SystemCertificates\SmartCardRoot"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtCreateKey, status:0x0, handle
:0x6B4, access:0x2000000, title:0x0, class:"", options:0x0, disposition:0x2, pat
h:"\REGISTRY\MACHINE\Software"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtCreateKey, status:0x0, handle
:0x6B8, access:0x2000000, title:0x0, class:"", options:0x0, disposition:0x2, pat
h:"\REGISTRY\MACHINE\Software\Microsoft"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
B4
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtCreateKey, status:0x0, handle
:0x6B4, access:0x2000000, title:0x0, class:"", options:0x0, disposition:0x2, pat
h:"\REGISTRY\MACHINE\Software\Microsoft\SystemCertificates"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
B8
pid:4092, tid:1488, tick:0x33D728F, lvl:LOG, func:NtCreateKey, status:0xC0000022
, handle:0x0, access:0x3001F, title:0x0, class:"", options:0x0, disposition:0x2,
path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\SystemCertificates\SmartCardRoot"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
B4
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x6BC, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\SystemCertifi
cates\SmartCardRoot"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
BC

pid:4092, tid:1488, tick:0x33D728F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034


, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\SystemC
ertificates\CA\PhysicalStores"
pid:4092, tid:1488, tick:0x33D728F, lvl:LOG, func:NtCreateKey, status:0xC0000022
, handle:0x0, access:0x3001F, title:0x0, class:"", options:0x0, disposition:0x77
C8ED50, path:"\REGISTRY\MACHINE\Software\Microsoft\SystemCertificates\CA"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtCreateKey, status:0x0, handle
:0x6B0, access:0x2000000, title:0x0, class:"", options:0x0, disposition:0x2, pat
h:"\REGISTRY\MACHINE\Software"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtCreateKey, status:0x0, handle
:0x6B4, access:0x2000000, title:0x0, class:"", options:0x0, disposition:0x2, pat
h:"\REGISTRY\MACHINE\Software\Microsoft"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
B0
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtCreateKey, status:0x0, handle
:0x6B0, access:0x2000000, title:0x0, class:"", options:0x0, disposition:0x2, pat
h:"\REGISTRY\MACHINE\Software\Microsoft\SystemCertificates"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
B4
pid:4092, tid:1488, tick:0x33D728F, lvl:LOG, func:NtCreateKey, status:0xC0000022
, handle:0x0, access:0x3001F, title:0x0, class:"", options:0x0, disposition:0x2,
path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\SystemCertificates\CA"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
B0
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x6BC, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\SystemCertifi
cates\CA"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
BC
pid:4092, tid:1488, tick:0x33D728F, lvl:LOG, func:NtCreateKey, status:0xC0000022
, handle:0x0, access:0x3001F, title:0x0, class:"", options:0x0, disposition:0x1,
path:"\REGISTRY\MACHINE\Software\Microsoft\SystemCertificates\CA"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtCreateKey, status:0x0, handle
:0x6BC, access:0x2000000, title:0x0, class:"", options:0x0, disposition:0x2, pat
h:"\REGISTRY\MACHINE\Software"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtCreateKey, status:0x0, handle
:0x6C0, access:0x2000000, title:0x0, class:"", options:0x0, disposition:0x2, pat
h:"\REGISTRY\MACHINE\Software\Microsoft"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
BC
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtCreateKey, status:0x0, handle
:0x6BC, access:0x2000000, title:0x0, class:"", options:0x0, disposition:0x2, pat
h:"\REGISTRY\MACHINE\Software\Microsoft\SystemCertificates"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
C0
pid:4092, tid:1488, tick:0x33D728F, lvl:LOG, func:NtCreateKey, status:0xC0000022
, handle:0x0, access:0x3001F, title:0x0, class:"", options:0x0, disposition:0x2,
path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\SystemCertificates\CA"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
BC
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x6BC, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\SystemCertifi
cates\CA"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x6C0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\SystemCertifi
cates\CA\"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
BC
pid:4092, tid:1488, tick:0x33D728F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Enterpr

iseCertificates\CA\PhysicalStores"
pid:4092, tid:1488, tick:0x33D728F, lvl:LOG, func:NtCreateKey, status:0xC0000022
, handle:0x0, access:0x3001F, title:0x0, class:"", options:0x0, disposition:0xFF
FFFFFE, path:"\REGISTRY\MACHINE\Software\Microsoft\EnterpriseCertificates\CA"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtCreateKey, status:0x0, handle
:0x6BC, access:0x2000000, title:0x0, class:"", options:0x0, disposition:0x2, pat
h:"\REGISTRY\MACHINE\Software"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtCreateKey, status:0x0, handle
:0x6C4, access:0x2000000, title:0x0, class:"", options:0x0, disposition:0x2, pat
h:"\REGISTRY\MACHINE\Software\Microsoft"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
BC
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtCreateKey, status:0x0, handle
:0x6BC, access:0x2000000, title:0x0, class:"", options:0x0, disposition:0x2, pat
h:"\REGISTRY\MACHINE\Software\Microsoft\EnterpriseCertificates"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
C4
pid:4092, tid:1488, tick:0x33D728F, lvl:LOG, func:NtCreateKey, status:0xC0000022
, handle:0x0, access:0x3001F, title:0x0, class:"", options:0x0, disposition:0x2,
path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\EnterpriseCertificates\CA"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
BC
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x6BC, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\EnterpriseCer
tificates\CA"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
BC
pid:4092, tid:1488, tick:0x33D728F, lvl:LOG, func:NtCreateKey, status:0xC0000022
, handle:0x0, access:0x3001F, title:0x0, class:"", options:0x0, disposition:0x1,
path:"\REGISTRY\MACHINE\Software\Microsoft\EnterpriseCertificates\CA"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtCreateKey, status:0x0, handle
:0x6BC, access:0x2000000, title:0x0, class:"", options:0x0, disposition:0x2, pat
h:"\REGISTRY\MACHINE\Software"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtCreateKey, status:0x0, handle
:0x6C4, access:0x2000000, title:0x0, class:"", options:0x0, disposition:0x2, pat
h:"\REGISTRY\MACHINE\Software\Microsoft"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
BC
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtCreateKey, status:0x0, handle
:0x6BC, access:0x2000000, title:0x0, class:"", options:0x0, disposition:0x2, pat
h:"\REGISTRY\MACHINE\Software\Microsoft\EnterpriseCertificates"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
C4
pid:4092, tid:1488, tick:0x33D728F, lvl:LOG, func:NtCreateKey, status:0xC0000022
, handle:0x0, access:0x3001F, title:0x0, class:"", options:0x0, disposition:0x2,
path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\EnterpriseCertificates\CA"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
BC
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x6BC, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\EnterpriseCer
tificates\CA"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x6C4, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\EnterpriseCer
tificates\CA\"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
BC
pid:4092, tid:1488, tick:0x33D728F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"AutoFlags", class:0x2, length:0x90, resultlength:0x64, handle:0x6A0,
path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Cryptography\OID\EncodingType 0\Cert
DllCreateCertificateChainEngine\Config"

pid:4092, tid:1488, tick:0x33D728F, lvl:LOG, func:NtQueryValueKey, status:0xC000


0034, name:"DisableAutoFlushProcessNameList", class:0x2, length:0x90, resultleng
th:0x2020E48, handle:0x6A0, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Cryptogra
phy\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config"
pid:4092, tid:1488, tick:0x33D728F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"AutoFlushFirstDeltaSeconds", class:0x2, length:0x90, resultlength:0x
0, handle:0x6A0, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Cryptography\OID\Enc
odingType 0\CertDllCreateCertificateChainEngine\Config"
pid:4092, tid:1488, tick:0x33D728F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"AutoFlushNextDeltaSeconds", class:0x2, length:0x90, resultlength:0x0
, handle:0x6A0, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Cryptography\OID\Enco
dingType 0\CertDllCreateCertificateChainEngine\Config"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
A0
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x6A0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\SystemCertifi
cates\ROOT\Certificates"
pid:4092, tid:1488, tick:0x33D728F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"104C63D2546B8021DD105E9FBA5A8D78169F6B32", class:0x2, length:0x90, r
esultlength:0x331F37C, handle:0x6A0, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\
SystemCertificates\ROOT\Certificates"
pid:4092, tid:1488, tick:0x33D728F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\SystemC
ertificates\ROOT\Certificates\104C63D2546B8021DD105E9FBA5A8D78169F6B32"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
A0
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x6A0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\SystemCertifi
cates\AuthRoot\Certificates"
pid:4092, tid:1488, tick:0x33D728F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"104C63D2546B8021DD105E9FBA5A8D78169F6B32", class:0x2, length:0x90, r
esultlength:0x124B218, handle:0x6A0, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\
SystemCertificates\AuthRoot\Certificates"
pid:4092, tid:1488, tick:0x33D728F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\SystemC
ertificates\AuthRoot\Certificates\104C63D2546B8021DD105E9FBA5A8D78169F6B32"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
A0
pid:4092, tid:1488, tick:0x33D728F, lvl:LOG, func:NtCreateKey, status:0xC0000022
, handle:0x0, access:0x3001F, title:0x0, class:"", options:0x0, disposition:0x68
0000, path:"\REGISTRY\MACHINE\Software\Policies\Microsoft\SystemCertificates\Roo
t"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtCreateKey, status:0x0, handle
:0x6A0, access:0x2000000, title:0x0, class:"", options:0x0, disposition:0x2, pat
h:"\REGISTRY\MACHINE\Software"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtCreateKey, status:0x0, handle
:0x6BC, access:0x2000000, title:0x0, class:"", options:0x0, disposition:0x2, pat
h:"\REGISTRY\MACHINE\Software\Policies"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
A0
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtCreateKey, status:0x0, handle
:0x6A0, access:0x2000000, title:0x0, class:"", options:0x0, disposition:0x2, pat
h:"\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
BC
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtCreateKey, status:0x0, handle
:0x6BC, access:0x2000000, title:0x0, class:"", options:0x0, disposition:0x2, pat
h:"\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
A0

pid:4092, tid:1488, tick:0x33D728F, lvl:LOG, func:NtCreateKey, status:0xC0000022


, handle:0x0, access:0x3001F, title:0x0, class:"", options:0x0, disposition:0x2,
path:"\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\Root"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
BC
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x6BC, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\EnterpriseCer
tificates\Root\Certificates"
pid:4092, tid:1488, tick:0x33D728F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"104C63D2546B8021DD105E9FBA5A8D78169F6B32", class:0x2, length:0x90, r
esultlength:0x0, handle:0x6BC, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Enterp
riseCertificates\Root\Certificates"
pid:4092, tid:1488, tick:0x33D728F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Enterpr
iseCertificates\Root\Certificates\104C63D2546B8021DD105E9FBA5A8D78169F6B32"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
BC
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x6BC, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\SystemCertifi
cates\CA\Certificates"
pid:4092, tid:1488, tick:0x33D728F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"104C63D2546B8021DD105E9FBA5A8D78169F6B32", class:0x2, length:0x90, r
esultlength:0x124B790, handle:0x6BC, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\
SystemCertificates\CA\Certificates"
pid:4092, tid:1488, tick:0x33D728F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\SystemC
ertificates\CA\Certificates\104C63D2546B8021DD105E9FBA5A8D78169F6B32"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
BC
pid:4092, tid:1488, tick:0x33D728F, lvl:LOG, func:NtCreateKey, status:0xC0000022
, handle:0x0, access:0x3001F, title:0x0, class:"", options:0x0, disposition:0x68
0000, path:"\REGISTRY\MACHINE\Software\Policies\Microsoft\SystemCertificates\CA"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtCreateKey, status:0x0, handle
:0x6BC, access:0x2000000, title:0x0, class:"", options:0x0, disposition:0x2, pat
h:"\REGISTRY\MACHINE\Software"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtCreateKey, status:0x0, handle
:0x6A0, access:0x2000000, title:0x0, class:"", options:0x0, disposition:0x2, pat
h:"\REGISTRY\MACHINE\Software\Policies"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
BC
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtCreateKey, status:0x0, handle
:0x6BC, access:0x2000000, title:0x0, class:"", options:0x0, disposition:0x2, pat
h:"\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
A0
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtCreateKey, status:0x0, handle
:0x6A0, access:0x2000000, title:0x0, class:"", options:0x0, disposition:0x2, pat
h:"\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
BC
pid:4092, tid:1488, tick:0x33D728F, lvl:LOG, func:NtCreateKey, status:0xC0000022
, handle:0x0, access:0x3001F, title:0x0, class:"", options:0x0, disposition:0x2,
path:"\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\CA"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
A0
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x6A0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\EnterpriseCer
tificates\CA\Certificates"
pid:4092, tid:1488, tick:0x33D728F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"104C63D2546B8021DD105E9FBA5A8D78169F6B32", class:0x2, length:0x90, r

esultlength:0x0, handle:0x6A0, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Enterp


riseCertificates\CA\Certificates"
pid:4092, tid:1488, tick:0x33D728F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Enterpr
iseCertificates\CA\Certificates\104C63D2546B8021DD105E9FBA5A8D78169F6B32"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
A0
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x6A0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\SystemCertifi
cates\ROOT\Certificates"
pid:4092, tid:1488, tick:0x33D728F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"AFE5D244A8D1194230FF479FE2F897BBCD7A8CB4", class:0x2, length:0x90, r
esultlength:0x124B218, handle:0x6A0, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\
SystemCertificates\ROOT\Certificates"
pid:4092, tid:1488, tick:0x33D728F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\SystemC
ertificates\ROOT\Certificates\AFE5D244A8D1194230FF479FE2F897BBCD7A8CB4"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
A0
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x6A0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\SystemCertifi
cates\AuthRoot\Certificates"
pid:4092, tid:1488, tick:0x33D728F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"AFE5D244A8D1194230FF479FE2F897BBCD7A8CB4", class:0x2, length:0x90, r
esultlength:0x124B218, handle:0x6A0, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\
SystemCertificates\AuthRoot\Certificates"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x6BC, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\SystemCertifi
cates\AuthRoot\Certificates\AFE5D244A8D1194230FF479FE2F897BBCD7A8CB4"
pid:4092, tid:1488, tick:0x33D728F, lvl:LOG, func:NtQueryValueKey, status:0x8000
0005, name:"Blob", class:0x2, length:0x90, resultlength:0x7BC, handle:0x6BC, pat
h:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\SystemCertificates\AuthRoot\Certificates
\AFE5D244A8D1194230FF479FE2F897BBCD7A8CB4"
pid:4092, tid:1488, tick:0x33D728F, lvl:LOG, func:NtQueryValueKey, status:0x8000
0005, name:"Blob", class:0x2, length:0x90, resultlength:0x7BC, handle:0x6BC, pat
h:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\SystemCertificates\AuthRoot\Certificates
\AFE5D244A8D1194230FF479FE2F897BBCD7A8CB4"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Blob", class:0x2, length:0x7BC, resultlength:0x7BC, handle:0x6BC, path:"\REG
ISTRY\MACHINE\SOFTWARE\MICROSOFT\SystemCertificates\AuthRoot\Certificates\AFE5D2
44A8D1194230FF479FE2F897BBCD7A8CB4"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
BC
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
A0
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x6A0, access:0x20119, path:"\REGISTRY\MACHINE\Software\Microsoft\SystemCertifi
cates\AuthRoot\AutoUpdate"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"DisallowedCertLastSyncTime", class:0x2, length:0x90, resultlength:0x14, hand
le:0x6A0, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\SystemCertificates\AuthRoot
\AutoUpdate"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
A0
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
BC
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
A0
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x6A0, c

lass:0x1D, length:0x4, returnlength:0x4


pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
A0
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x6A0, c
lass:0x1, length:0x100, returnlength:0x24, sid:"S-1-5-21-2360094602-2602383397-2
463990887-1001", attributes:0x0
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
A0
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x6BC, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x6C8, access:0x20119, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\SystemCertificates\AuthRoot\AutoUpdate"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
BC
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"DisallowedCertLastSyncTime", class:0x2, length:0x90, resultlength:0x14, hand
le:0x6C8, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SO
FTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdate"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
C8
pid:4092, tid:8264, tick:0x33D728F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x698, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptography\
OID"
pid:4092, tid:8264, tick:0x33D728F, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x0, class:0x0, length:0x120, resultlength:0x2C, handle:0x698, path:"\REGISTR
Y\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID"
pid:4092, tid:8264, tick:0x33D728F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x69C, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\C
ryptography\OID\EncodingType 0"
pid:4092, tid:8264, tick:0x33D728F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Micro
soft\Cryptography\OID\EncodingType 0\CertDllVerifyRevocation"
pid:4092, tid:8264, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
9C
pid:4092, tid:8264, tick:0x33D728F, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1, class:0x0, length:0x120, resultlength:0x2C, handle:0x698, path:"\REGISTR
Y\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID"
pid:4092, tid:8264, tick:0x33D728F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x6B8, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\C
ryptography\OID\EncodingType 1"
pid:4092, tid:8264, tick:0x33D728F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x668, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\C
ryptography\OID\EncodingType 1\CertDllVerifyRevocation"
pid:4092, tid:8264, tick:0x33D728F, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x0, class:0x0, length:0x120, resultlength:0x1E, handle:0x668, path:"\REGISTR
Y\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CertDll
VerifyRevocation"
pid:4092, tid:8264, tick:0x33D728F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x664, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\C
ryptography\OID\EncodingType 1\CertDllVerifyRevocation\DEFAULT"
pid:4092, tid:8264, tick:0x33D728F, lvl:OK, func:NtQueryKey, status:0x0, class:0
x4, length:0xB0, resultlength:0x28, handle:0x664, path:"\REGISTRY\MACHINE\SOFTWA
RE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CertDllVerifyRevocation
\DEFAULT"
pid:4092, tid:8264, tick:0x33D728F, lvl:OK, func:NtEnumerateValueKey, status:0x0
, index:0x0, class:0x1, length:0xDC, resultlength:0x64, handle:0x664, path:"\REG
ISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\Cer

tDllVerifyRevocation\DEFAULT"
pid:4092, tid:8264, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
64
pid:4092, tid:8264, tick:0x33D728F, lvl:LOG, func:NtEnumerateKey, status:0x80000
01A, index:0x1, class:0x0, length:0x120, resultlength:0x0, handle:0x668, path:"\
REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\
CertDllVerifyRevocation"
pid:4092, tid:8264, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
68
pid:4092, tid:8264, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
B8
pid:4092, tid:8264, tick:0x33D728F, lvl:LOG, func:NtEnumerateKey, status:0x80000
01A, index:0x2, class:0x0, length:0x120, resultlength:0x0, handle:0x698, path:"\
REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID"
pid:4092, tid:8264, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
98
pid:4092, tid:8264, tick:0x33D728F, lvl:LOG, func:NtOpenSection, status:0xC00000
34, handle:0x0, access:0xF, path:"\KnownDlls32\cryptnet.dll"
pid:4092, tid:8264, tick:0x33D728F, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x20, path:"C:\Windows\SYSTEM32\cryptnet.dll"
pid:4092, tid:8264, tick:0x33D728F, lvl:OK, func:NtOpenFile, status:0x0, handle:
0x6D4, access:0x100021, iostatus:0x0, information:0x1, share:0x5, options:0x60,
path:"C:\Windows\SYSTEM32\cryptnet.dll"
pid:4092, tid:8264, tick:0x33D728F, lvl:OK, func:NtCreateSection, status:0x0, ha
ndle:0x6D8, access:0xF, pageattribs:0x10, sectionattribs:0x1000000, file:0x6D4
pid:4092, tid:8264, tick:0x33D728F, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x60BF0000, zerobits:0x0, commitsize:0x0, viewsize:0x25000, disposition
:0x1, type:0x800000, protect:0x4, handle:0x6D8, path:"C:\Windows\SYSTEM32\cryptn
et.dll"
pid:4092, tid:8264, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
D8
pid:4092, tid:8264, tick:0x33D729F, lvl:OK, func:NtClose, status:0x0, handle:0x6
D4
pid:4092, tid:8264, tick:0x33D729F, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x2, module:"C:\Windows\SYSTEM32\cryptnet.dll", handle:0x60BF0000
pid:4092, tid:8264, tick:0x33D729F, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x2, module:"C:\Windows\SYSTEM32\cryptnet.dll", handle:0x60BF0000
pid:4092, tid:8264, tick:0x33D729F, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x2, module:"C:\Windows\SYSTEM32\cryptnet.dll", handle:0x60BF0000
pid:4092, tid:8264, tick:0x33D729F, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x2, module:"C:\Windows\SYSTEM32\cryptnet.dll", handle:0x60BF0000
pid:4092, tid:8264, tick:0x33D729F, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x2, module:"C:\Windows\SYSTEM32\cryptnet.dll", handle:0x60BF0000
pid:4092, tid:8264, tick:0x33D729F, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x2, module:"C:\Windows\SYSTEM32\cryptnet.dll", handle:0x60BF0000
pid:4092, tid:8264, tick:0x33D729F, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x2, module:"C:\Windows\SYSTEM32\cryptnet.dll", handle:0x60BF0000
pid:4092, tid:8264, tick:0x33D729F, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x2, module:"C:\Windows\SYSTEM32\cryptnet.dll", handle:0x60BF0000
pid:4092, tid:8264, tick:0x33D729F, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x2, module:"C:\Windows\SYSTEM32\cryptnet.dll", handle:0x60BF0000
pid:4092, tid:8264, tick:0x33D729F, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x2, module:"C:\Windows\SYSTEM32\cryptnet.dll", handle:0x60BF0000
pid:4092, tid:8264, tick:0x33D729F, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x2, module:"C:\Windows\SYSTEM32\cryptnet.dll", handle:0x60BF0000
pid:4092, tid:8264, tick:0x33D729F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptog
raphy\TVO"
pid:4092, tid:8264, tick:0x33D729F, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"C:\Windows\SysWOW64\cryptnet.dll", handle:0x60BF0000

pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:LdrLoadDll, status:0x0, flags:0


x0, module:"C:\Windows\SysWOW64\cryptnet.dll", handle:0x60BF0000
pid:4092, tid:8264, tick:0x33D729F, lvl:LOG, func:LdrGetProcedureAddressForCalle
r, status:0xC0000139, module:0x60BF0000, name:"DllCanUnloadNow", ordinal:0x0, im
age:0x0, caller:0x778A2540
pid:4092, tid:1488, tick:0x33D729F, lvl:LOG, func:LdrGetProcedureAddressForCalle
r, status:0xC0000139, module:0x60BF0000, name:"DllCanUnloadNow", ordinal:0x0, im
age:0x0, caller:0x778A2540
pid:4092, tid:8264, tick:0x33D729F, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x60BF0000, name:"CertDllVerifyRevocation", ordinal:0x0, ad
dress:0x60BF9DB0, image:0x0, caller:0x778A3452
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:LdrUnloadDll, status:0x0, handl
e:0x60BF0000
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x60BF0000, name:"CertDllVerifyRevocation", ordinal:0x0, ad
dress:0x60BF9DB0, image:0x0, caller:0x778A3452
pid:4092, tid:8264, tick:0x33D729F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x664, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptography\
OID"
pid:4092, tid:8264, tick:0x33D729F, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x0, class:0x0, length:0x120, resultlength:0x2C, handle:0x664, path:"\REGISTR
Y\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID"
pid:4092, tid:8264, tick:0x33D729F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x5F4, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\C
ryptography\OID\EncodingType 0"
pid:4092, tid:8264, tick:0x33D729F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Micro
soft\Cryptography\OID\EncodingType 0\TimeValidDllGetObject"
pid:4092, tid:8264, tick:0x33D729F, lvl:OK, func:NtClose, status:0x0, handle:0x5
F4
pid:4092, tid:8264, tick:0x33D729F, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1, class:0x0, length:0x120, resultlength:0x2C, handle:0x664, path:"\REGISTR
Y\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID"
pid:4092, tid:8264, tick:0x33D729F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x698, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\C
ryptography\OID\EncodingType 1"
pid:4092, tid:8264, tick:0x33D729F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Micro
soft\Cryptography\OID\EncodingType 1\TimeValidDllGetObject"
pid:4092, tid:8264, tick:0x33D729F, lvl:OK, func:NtClose, status:0x0, handle:0x6
98
pid:4092, tid:8264, tick:0x33D729F, lvl:LOG, func:NtEnumerateKey, status:0x80000
01A, index:0x2, class:0x0, length:0x120, resultlength:0x0, handle:0x664, path:"\
REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID"
pid:4092, tid:8264, tick:0x33D729F, lvl:OK, func:NtClose, status:0x0, handle:0x6
64
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x5F4, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptography\
OID"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x0, class:0x0, length:0x120, resultlength:0x2C, handle:0x5F4, path:"\REGISTR
Y\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x670, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\C
ryptography\OID\EncodingType 0"
pid:4092, tid:1488, tick:0x33D729F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Micro
soft\Cryptography\OID\EncodingType 0\UrlDllGetObjectUrl"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtClose, status:0x0, handle:0x6
70

pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtEnumerateKey, status:0x0, ind


ex:0x1, class:0x0, length:0x120, resultlength:0x2C, handle:0x5F4, path:"\REGISTR
Y\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x670, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\C
ryptography\OID\EncodingType 1"
pid:4092, tid:1488, tick:0x33D729F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Micro
soft\Cryptography\OID\EncodingType 1\UrlDllGetObjectUrl"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtClose, status:0x0, handle:0x6
70
pid:4092, tid:1488, tick:0x33D729F, lvl:LOG, func:NtEnumerateKey, status:0x80000
01A, index:0x2, class:0x0, length:0x120, resultlength:0x0, handle:0x5F4, path:"\
REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtClose, status:0x0, handle:0x5
F4
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x5F4, access:0x20119, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptography\
OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config"
pid:4092, tid:1488, tick:0x33D729F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"CryptnetCachedOcspSwitchToCrlCount", class:0x2, length:0x90, resultl
ength:0x0, handle:0x5F4, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Cryptography
\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config"
pid:4092, tid:1488, tick:0x33D729F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"CryptnetMaxCachedOcspPerCrlCount", class:0x2, length:0x90, resultlen
gth:0x0, handle:0x5F4, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Cryptography\O
ID\EncodingType 0\CertDllCreateCertificateChainEngine\Config"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtClose, status:0x0, handle:0x5
F4
pid:4092, tid:1488, tick:0x33D729F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies\Microsof
t\SystemCertificates\ChainEngine\Config"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtClose, status:0x0, handle:0x6
70
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtClose, status:0x0, handle:0x5
F4
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x5F4, c
lass:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x60BF0000
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x670, c
lass:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x674, c
lass:0x1, length:0xC8, returnlength:0x24, sid:"S-1-5-21-2360094602-2602383397-24
63990887-1001", attributes:0x0
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x75430000
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtClose, status:0x0, handle:0x6
74
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x6DC, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folder
s"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Local AppData", class:0x2, length:0x90, resultlength:0x44, handle:0x6DC, pat
h:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Micros
oft\Windows\CurrentVersion\Explorer\User Shell Folders"

pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryValueKey, status:0x0, na


me:"Local AppData", class:0x2, length:0x90, resultlength:0x44, handle:0x6DC, pat
h:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Micros
oft\Windows\CurrentVersion\Explorer\User Shell Folders"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x6E0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows NT\Cu
rrentVersion\ProfileList\S-1-5-21-2360094602-2602383397-2463990887-1001"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ProfileImagePath", class:0x2, length:0x90, resultlength:0x30, handle:0x6E0,
path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\ProfileList
\S-1-5-21-2360094602-2602383397-2463990887-1001"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ProfileImagePath", class:0x2, length:0x90, resultlength:0x30, handle:0x6E0,
path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\ProfileList
\S-1-5-21-2360094602-2602383397-2463990887-1001"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtClose, status:0x0, handle:0x6
E0
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtClose, status:0x0, handle:0x6
DC
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtClose, status:0x0, handle:0x6
70
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x2010, path:"C:\Users\i92segoa\AppData\LocalLow"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtOpenFile, status:0x0, handle:
0x6DC, access:0x20000, iostatus:0x0, information:0x1, share:0x7, options:0x20000
0, path:"C:\Users\i92segoa\AppData\LocalLow"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQuerySecurityObject, status:0
x0, class:0x10, length:0x400, requiredlength:0x30, handle:0x6DC, path:"C:\Users\
i92segoa\AppData\LocalLow"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtClose, status:0x0, handle:0x6
DC
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtClose, status:0x0, handle:0x5
F4
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5A0000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x670000
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x670000, zerobits:0x0, commitsize:0x0, offset:0x1E0000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5A0000
pid:4092, tid:1488, tick:0x33D729F, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding directory LastPass with flags: 2."
pid:4092, tid:1488, tick:0x33D729F, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding directory Microsoft with flags: 4."
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtClose, status:0x0, handle:0x5
F4
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5A0000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x670000
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x670000, zerobits:0x0, commitsize:0x0, offset:0x1E0000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5A0000
pid:4092, tid:1488, tick:0x33D729F, lvl:LOG, func:RecurseDirectoryConfig, log:"A

dding directory CryptnetUrlCache with flags: 4."


pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtClose, status:0x0, handle:0x5
F4
pid:4092, tid:1488, tick:0x33D729F, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding directory Content with flags: 4."
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtClose, status:0x0, handle:0x5
F4
pid:4092, tid:1488, tick:0x33D729F, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding directory MetaData with flags: 4."
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtClose, status:0x0, handle:0x5
F4
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtOpenFile, status:0x0, handle:
0x5F4, access:0x100001, iostatus:0x0, information:0x0, share:0x7, options:0x4021
, path:"C:\Users\i92segoa\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryDirectoryFile, status:0x
0, iostatus:0x0, information:0xE0, length:0x268, class:0x3, single:0x1, mask:"50
80DC7A65DB6A5960ECD874088F3328_*", restart:0x0, handle:0x5F4, path:"C:\Users\i92
segoa\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryDirectoryFile, status:0x
0, iostatus:0x0, information:0x2A0, length:0x1000, class:0x3, single:0x0, restar
t:0x0, handle:0x5F4, path:"C:\Users\i92segoa\AppData\LocalLow\Microsoft\Cryptnet
UrlCache\MetaData"
pid:4092, tid:1488, tick:0x33D729F, lvl:LOG, func:NtQueryDirectoryFile, status:0
x80000006, iostatus:0x80000006, information:0x0, length:0x1000, class:0x3, singl
e:0x0, restart:0x0, handle:0x5F4, path:"C:\Users\i92segoa\AppData\LocalLow\Micro
soft\CryptnetUrlCache\MetaData"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtClose, status:0x0, handle:0x5
F4
pid:4092, tid:1488, tick:0x33D729F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20119, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptog
raphy\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\CrlPreFetch"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x5F4, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptography\
OID"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x0, class:0x0, length:0x120, resultlength:0x2C, handle:0x5F4, path:"\REGISTR
Y\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x670, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\C
ryptography\OID\EncodingType 0"
pid:4092, tid:1488, tick:0x33D729F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Micro
soft\Cryptography\OID\EncodingType 0\CryptDllEncodeObjectEx"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtClose, status:0x0, handle:0x6
70
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1, class:0x0, length:0x120, resultlength:0x2C, handle:0x5F4, path:"\REGISTR
Y\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x670, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\C
ryptography\OID\EncodingType 1"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x6DC, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\C
ryptography\OID\EncodingType 1\CryptDllEncodeObjectEx"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x0, class:0x0, length:0x120, resultlength:0x42, handle:0x6DC, path:"\REGISTR
Y\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDl
lEncodeObjectEx"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x6E0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\C

ryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.1.1"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryKey, status:0x0, class:0
x4, length:0xB0, resultlength:0x28, handle:0x6E0, path:"\REGISTRY\MACHINE\SOFTWA
RE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\
1.2.840.113549.1.9.16.1.1"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtEnumerateValueKey, status:0x0
, index:0x0, class:0x1, length:0xDC, resultlength:0x62, handle:0x6E0, path:"\REG
ISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\Cry
ptDllEncodeObjectEx\1.2.840.113549.1.9.16.1.1"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtEnumerateValueKey, status:0x0
, index:0x1, class:0x1, length:0xDC, resultlength:0x4E, handle:0x6E0, path:"\REG
ISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\Cry
ptDllEncodeObjectEx\1.2.840.113549.1.9.16.1.1"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtClose, status:0x0, handle:0x6
E0
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1, class:0x0, length:0x120, resultlength:0x42, handle:0x6DC, path:"\REGISTR
Y\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDl
lEncodeObjectEx"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x69C, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\C
ryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.1"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryKey, status:0x0, class:0
x4, length:0xB0, resultlength:0x28, handle:0x69C, path:"\REGISTRY\MACHINE\SOFTWA
RE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\
1.2.840.113549.1.9.16.2.1"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtEnumerateValueKey, status:0x0
, index:0x0, class:0x1, length:0xDC, resultlength:0x62, handle:0x69C, path:"\REG
ISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\Cry
ptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.1"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtEnumerateValueKey, status:0x0
, index:0x1, class:0x1, length:0xDC, resultlength:0x5C, handle:0x69C, path:"\REG
ISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\Cry
ptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.1"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtClose, status:0x0, handle:0x6
9C
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x2, class:0x0, length:0x120, resultlength:0x44, handle:0x6DC, path:"\REGISTR
Y\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDl
lEncodeObjectEx"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x69C, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\C
ryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.11
"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryKey, status:0x0, class:0
x4, length:0xB0, resultlength:0x28, handle:0x69C, path:"\REGISTRY\MACHINE\SOFTWA
RE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\
1.2.840.113549.1.9.16.2.11"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtEnumerateValueKey, status:0x0
, index:0x0, class:0x1, length:0xDC, resultlength:0x62, handle:0x69C, path:"\REG
ISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\Cry
ptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.11"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtEnumerateValueKey, status:0x0
, index:0x1, class:0x1, length:0xDC, resultlength:0x62, handle:0x69C, path:"\REG
ISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\Cry
ptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.11"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtClose, status:0x0, handle:0x6
9C
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x3, class:0x0, length:0x120, resultlength:0x44, handle:0x6DC, path:"\REGISTR

Y\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDl
lEncodeObjectEx"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x69C, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\C
ryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.12
"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryKey, status:0x0, class:0
x4, length:0xB0, resultlength:0x28, handle:0x69C, path:"\REGISTRY\MACHINE\SOFTWA
RE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\
1.2.840.113549.1.9.16.2.12"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtEnumerateValueKey, status:0x0
, index:0x0, class:0x1, length:0xDC, resultlength:0x62, handle:0x69C, path:"\REG
ISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\Cry
ptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.12"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtEnumerateValueKey, status:0x0
, index:0x1, class:0x1, length:0xDC, resultlength:0x5E, handle:0x69C, path:"\REG
ISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\Cry
ptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.12"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtClose, status:0x0, handle:0x6
9C
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x4, class:0x0, length:0x120, resultlength:0x42, handle:0x6DC, path:"\REGISTR
Y\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDl
lEncodeObjectEx"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x69C, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\C
ryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.2"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryKey, status:0x0, class:0
x4, length:0xB0, resultlength:0x28, handle:0x69C, path:"\REGISTRY\MACHINE\SOFTWA
RE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\
1.2.840.113549.1.9.16.2.2"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtEnumerateValueKey, status:0x0
, index:0x0, class:0x1, length:0xDC, resultlength:0x62, handle:0x69C, path:"\REG
ISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\Cry
ptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.2"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtEnumerateValueKey, status:0x0
, index:0x1, class:0x1, length:0xDC, resultlength:0x5A, handle:0x69C, path:"\REG
ISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\Cry
ptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.2"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtClose, status:0x0, handle:0x6
9C
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x5, class:0x0, length:0x120, resultlength:0x42, handle:0x6DC, path:"\REGISTR
Y\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDl
lEncodeObjectEx"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x69C, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\C
ryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.3"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryKey, status:0x0, class:0
x4, length:0xB0, resultlength:0x28, handle:0x69C, path:"\REGISTRY\MACHINE\SOFTWA
RE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\
1.2.840.113549.1.9.16.2.3"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtEnumerateValueKey, status:0x0
, index:0x0, class:0x1, length:0xDC, resultlength:0x62, handle:0x69C, path:"\REG
ISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\Cry
ptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.3"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtEnumerateValueKey, status:0x0
, index:0x1, class:0x1, length:0xDC, resultlength:0x52, handle:0x69C, path:"\REG
ISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\Cry
ptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.3"

pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtClose, status:0x0, handle:0x6


9C
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x6, class:0x0, length:0x120, resultlength:0x42, handle:0x6DC, path:"\REGISTR
Y\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDl
lEncodeObjectEx"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x69C, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\C
ryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.4"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryKey, status:0x0, class:0
x4, length:0xB0, resultlength:0x28, handle:0x69C, path:"\REGISTRY\MACHINE\SOFTWA
RE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\
1.2.840.113549.1.9.16.2.4"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtEnumerateValueKey, status:0x0
, index:0x0, class:0x1, length:0xDC, resultlength:0x62, handle:0x69C, path:"\REG
ISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\Cry
ptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.4"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtEnumerateValueKey, status:0x0
, index:0x1, class:0x1, length:0xDC, resultlength:0x56, handle:0x69C, path:"\REG
ISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\Cry
ptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.4"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtClose, status:0x0, handle:0x6
9C
pid:4092, tid:1488, tick:0x33D729F, lvl:LOG, func:NtEnumerateKey, status:0x80000
01A, index:0x7, class:0x0, length:0x120, resultlength:0x0, handle:0x6DC, path:"\
REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\
CryptDllEncodeObjectEx"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtClose, status:0x0, handle:0x6
DC
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtClose, status:0x0, handle:0x6
70
pid:4092, tid:1488, tick:0x33D729F, lvl:LOG, func:NtEnumerateKey, status:0x80000
01A, index:0x2, class:0x0, length:0x120, resultlength:0x0, handle:0x5F4, path:"\
REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtClose, status:0x0, handle:0x5
F4
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x5F4, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptography\
OID"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x670, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\C
ryptography\OID\EncodingType 0"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x6DC, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\C
ryptography\OID\EncodingType 0\CryptDllFindOIDInfo"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x0, class:0x0, length:0x120, resultlength:0x40, handle:0x6DC, path:"\REGISTR
Y\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDl
lFindOIDInfo"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x69C, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\C
ryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryKey, status:0x0, class:0
x4, length:0xB0, resultlength:0x28, handle:0x69C, path:"\REGISTRY\MACHINE\SOFTWA
RE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3
.6.1.4.1.311.64.1.1!7"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtEnumerateValueKey, status:0x0
, index:0x0, class:0x1, length:0xDC, resultlength:0x6E, handle:0x69C, path:"\REG
ISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\Cry
ptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7"

pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle


:0x6CC, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptography\
OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Name", class:0x2, length:0x90, resultlength:0x5A, handle:0x6CC, path:"\REGIS
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\Crypt
DllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x694, access:0x1, path:"\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\S
tringCacheSettings"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"StringCacheGeneration", class:0x1, length:0x214, resultlength:0x44, handle:0
x694, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\MUI\StringCacheSettin
gs"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtClose, status:0x0, handle:0x6
94
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x688, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x6B0, access:0x2001F, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246399
0887-1001\Software\Classes\Local Settings\MuiCache\a4\63C768CF"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtClose, status:0x0, handle:0x6
88
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtSetValueKey, status:0x0, name
:"LanguageList", index:0x0, type:0x7, size:0x26, handle:0x6B0, path:"\REGISTRY\U
SER\S-1-5-21-2360094602-2602383397-2463990887-1001_CLASSES\Local Settings\MuiCac
he\a4\63C768CF"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x20, path:"C:\WINDOWS\system32\dnsapi.dll"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"@%SystemRoot%\system32\dnsapi.dll,-103", class:0x1, length:0x214, resultleng
th:0xDA, handle:0x6B0, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24639
90887-1001_CLASSES\Local Settings\MuiCache\a4\63C768CF"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtClose, status:0x0, handle:0x6
B0
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Name", class:0x2, length:0x90, resultlength:0x5A, handle:0x6CC, path:"\REGIS
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\Crypt
DllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x6B0, access:0x1, path:"\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\S
tringCacheSettings"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"StringCacheGeneration", class:0x1, length:0x214, resultlength:0x44, handle:0
x6B0, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\MUI\StringCacheSettin
gs"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtClose, status:0x0, handle:0x6
B0
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x694, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001"

pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtOpenKey, status:0x0, handle:0


x688, access:0x2001F, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246399
0887-1001\Software\Classes\Local Settings\MuiCache\a4\63C768CF"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtClose, status:0x0, handle:0x6
94
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtSetValueKey, status:0x0, name
:"LanguageList", index:0x0, type:0x7, size:0x26, handle:0x688, path:"\REGISTRY\U
SER\S-1-5-21-2360094602-2602383397-2463990887-1001_CLASSES\Local Settings\MuiCac
he\a4\63C768CF"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x20, path:"C:\WINDOWS\system32\dnsapi.dll"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"@%SystemRoot%\system32\dnsapi.dll,-103", class:0x1, length:0x214, resultleng
th:0xDA, handle:0x688, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24639
90887-1001_CLASSES\Local Settings\MuiCache\a4\63C768CF"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtClose, status:0x0, handle:0x6
88
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtClose, status:0x0, handle:0x6
CC
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtClose, status:0x0, handle:0x6
9C
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1, class:0x0, length:0x120, resultlength:0x3C, handle:0x6DC, path:"\REGISTR
Y\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDl
lFindOIDInfo"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x69C, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\C
ryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.80.1!7"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryKey, status:0x0, class:0
x4, length:0xB0, resultlength:0x28, handle:0x69C, path:"\REGISTRY\MACHINE\SOFTWA
RE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3
.6.1.4.1.311.80.1!7"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtEnumerateValueKey, status:0x0
, index:0x0, class:0x1, length:0xDC, resultlength:0xA4, handle:0x69C, path:"\REG
ISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\Cry
ptDllFindOIDInfo\1.3.6.1.4.1.311.80.1!7"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x6CC, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptography\
OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.80.1!7"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Name", class:0x2, length:0x90, resultlength:0x90, handle:0x6CC, path:"\REGIS
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\Crypt
DllFindOIDInfo\1.3.6.1.4.1.311.80.1!7"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x688, access:0x1, path:"\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\S
tringCacheSettings"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"StringCacheGeneration", class:0x1, length:0x214, resultlength:0x44, handle:0
x688, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\MUI\StringCacheSettin
gs"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtClose, status:0x0, handle:0x6
88
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x6B0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtOpenKey, status:0x0, handle:0

x694, access:0x2001F, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246399


0887-1001\Software\Classes\Local Settings\MuiCache\a4\63C768CF"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtClose, status:0x0, handle:0x6
B0
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtSetValueKey, status:0x0, name
:"LanguageList", index:0x0, type:0x7, size:0x26, handle:0x694, path:"\REGISTRY\U
SER\S-1-5-21-2360094602-2602383397-2463990887-1001_CLASSES\Local Settings\MuiCac
he\a4\63C768CF"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x20, path:"C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.ex
e"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"@%SystemRoot%\system32\WindowsPowerShell\v1.0\powershell.exe,-124", class:0x
1, length:0x214, resultlength:0xC4, handle:0x694, path:"\REGISTRY\USER\S-1-5-212360094602-2602383397-2463990887-1001_CLASSES\Local Settings\MuiCache\a4\63C768C
F"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtClose, status:0x0, handle:0x6
94
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Name", class:0x2, length:0x90, resultlength:0x90, handle:0x6CC, path:"\REGIS
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\Crypt
DllFindOIDInfo\1.3.6.1.4.1.311.80.1!7"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x694, access:0x1, path:"\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\S
tringCacheSettings"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"StringCacheGeneration", class:0x1, length:0x214, resultlength:0x44, handle:0
x694, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\MUI\StringCacheSettin
gs"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtClose, status:0x0, handle:0x6
94
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x688, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x6B0, access:0x2001F, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246399
0887-1001\Software\Classes\Local Settings\MuiCache\a4\63C768CF"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtClose, status:0x0, handle:0x6
88
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtSetValueKey, status:0x0, name
:"LanguageList", index:0x0, type:0x7, size:0x26, handle:0x6B0, path:"\REGISTRY\U
SER\S-1-5-21-2360094602-2602383397-2463990887-1001_CLASSES\Local Settings\MuiCac
he\a4\63C768CF"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x20, path:"C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.ex
e"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"@%SystemRoot%\system32\WindowsPowerShell\v1.0\powershell.exe,-124", class:0x
1, length:0x214, resultlength:0xC4, handle:0x6B0, path:"\REGISTRY\USER\S-1-5-212360094602-2602383397-2463990887-1001_CLASSES\Local Settings\MuiCache\a4\63C768C
F"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtClose, status:0x0, handle:0x6
B0
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtClose, status:0x0, handle:0x6
CC
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtClose, status:0x0, handle:0x6

9C
pid:4092, tid:1488, tick:0x33D729F, lvl:LOG, func:NtEnumerateKey, status:0x80000
01A, index:0x2, class:0x0, length:0x120, resultlength:0x0, handle:0x6DC, path:"\
REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\
CryptDllFindOIDInfo"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtClose, status:0x0, handle:0x6
DC
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtClose, status:0x0, handle:0x6
70
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtClose, status:0x0, handle:0x5
F4
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x5F4, access:0x20119, path:"\REGISTRY\MACHINE\SYSTEM\CurrentControlSet\Control
\Cryptography\ECCParameters"
pid:4092, tid:1488, tick:0x33D729F, lvl:LOG, func:NtEnumerateKey, status:0x80000
01A, index:0x0, class:0x0, length:0x120, resultlength:0x0, handle:0x5F4, path:"\
REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Cryptography\ECCParameters"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtClose, status:0x0, handle:0x5
F4
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory, status:0x

0, address:0x2DBEAA8, class:0x3, length:0x14


pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,

status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x

0, address:0x2DBEAA8, class:0x3, length:0x14


pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,

status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x

0, address:0x2DBEAA8, class:0x3, length:0x14


pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,

status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x

0, address:0x2DBEAA8, class:0x3, length:0x14


pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,

status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x

0, address:0x2DBEAA8, class:0x3, length:0x14


pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,

status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x

0, address:0x2DBEAA8, class:0x3, length:0x14


pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory,

status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x

0, address:0x2DBEAA8, class:0x3, length:0x14


pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x5F4, access:0x20019, path:"\REGISTRY\MACHINE\SYSTEM\CurrentControlSet\Service
s\crypt32"
pid:4092, tid:1488, tick:0x33D729F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DebugFlags", class:0x2, length:0x90, resultlength:0x1F, handle:0x5F4
, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\crypt32"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtClose, status:0x0, handle:0x5
F4
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x5F4, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptography\
OID"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x0, class:0x0, length:0x120, resultlength:0x2C, handle:0x5F4, path:"\REGISTR
Y\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x670, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\C
ryptography\OID\EncodingType 0"
pid:4092, tid:1488, tick:0x33D729F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Micro
soft\Cryptography\OID\EncodingType 0\SchemeDllRetrieveEncodedObjectW"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtClose, status:0x0, handle:0x6
70
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1, class:0x0, length:0x120, resultlength:0x2C, handle:0x5F4, path:"\REGISTR
Y\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x670, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\C
ryptography\OID\EncodingType 1"
pid:4092, tid:1488, tick:0x33D729F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Micro
soft\Cryptography\OID\EncodingType 1\SchemeDllRetrieveEncodedObjectW"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtClose, status:0x0, handle:0x6
70
pid:4092, tid:1488, tick:0x33D729F, lvl:LOG, func:NtEnumerateKey, status:0x80000
01A, index:0x2, class:0x0, length:0x120, resultlength:0x0, handle:0x5F4, path:"\
REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtClose, status:0x0, handle:0x5
F4
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtClose, status:0x0, handle:0x6
70
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtClose, status:0x0, handle:0x5
F4
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x5F4, c
lass:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x670, c
lass:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:New_NtQueryInformationToken::<l

ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x6DC, c


lass:0x1, length:0xC8, returnlength:0x24, sid:"S-1-5-21-2360094602-2602383397-24
63990887-1001", attributes:0x0
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtClose, status:0x0, handle:0x6
DC
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x6DC, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folder
s"
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Local AppData", class:0x2, length:0x90, resultlength:0x44, handle:0x6DC, pat
h:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Micros
oft\Windows\CurrentVersion\Explorer\User Shell Folders"
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Local AppData", class:0x2, length:0x90, resultlength:0x44, handle:0x6DC, pat
h:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Micros
oft\Windows\CurrentVersion\Explorer\User Shell Folders"
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x69C, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows NT\Cu
rrentVersion\ProfileList\S-1-5-21-2360094602-2602383397-2463990887-1001"
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ProfileImagePath", class:0x2, length:0x90, resultlength:0x30, handle:0x69C,
path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\ProfileList
\S-1-5-21-2360094602-2602383397-2463990887-1001"
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ProfileImagePath", class:0x2, length:0x90, resultlength:0x30, handle:0x69C,
path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\ProfileList
\S-1-5-21-2360094602-2602383397-2463990887-1001"
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtClose, status:0x0, handle:0x6
9C
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtClose, status:0x0, handle:0x6
DC
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtClose, status:0x0, handle:0x6
70
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x2010, path:"C:\Users\i92segoa\AppData\LocalLow"
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtOpenFile, status:0x0, handle:
0x6DC, access:0x20000, iostatus:0x0, information:0x1, share:0x7, options:0x20000
0, path:"C:\Users\i92segoa\AppData\LocalLow"
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtQuerySecurityObject, status:0
x0, class:0x10, length:0x400, requiredlength:0x30, handle:0x6DC, path:"C:\Users\
i92segoa\AppData\LocalLow"
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtClose, status:0x0, handle:0x6
DC
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtClose, status:0x0, handle:0x5
F4
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtCreateFile, status:0x0, handl
e:0x670, access:0x80100080, iostatus:0x0, information:0x1, attribs:0x80, share:0
x1, disposition:0x1, options:0x60, path:"C:\Users\i92segoa\AppData\LocalLow\Micr
osoft\CryptnetUrlCache\MetaData\5080DC7A65DB6A5960ECD874088F3328_2908F682DFC81A7
93BD240CF29711C77"
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtCreateFile, status:0x0, handl
e:0x5F4, access:0x80100080, iostatus:0x0, information:0x1, attribs:0x80, share:0
x1, disposition:0x1, options:0x60, path:"C:\Users\i92segoa\AppData\LocalLow\Micr
osoft\CryptnetUrlCache\Content\5080DC7A65DB6A5960ECD874088F3328_2908F682DFC81A79
3BD240CF29711C77"
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtQueryInformationFile, status:
0x0, iostatus:0x0, information:0x18, length:0x18, class:0x5, handle:0x670, path:
"C:\Users\i92segoa\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\5080DC7A
65DB6A5960ECD874088F3328_2908F682DFC81A793BD240CF29711C77"

pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtReadFile, status:0x0, iostatu


s:0x0, information:0x4, length:0x4, handle:0x670, path:"C:\Users\i92segoa\AppDat
a\LocalLow\Microsoft\CryptnetUrlCache\MetaData\5080DC7A65DB6A5960ECD874088F3328_
2908F682DFC81A793BD240CF29711C77"
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtReadFile, status:0x0, iostatu
s:0x0, information:0x6C, length:0x6C, handle:0x670, path:"C:\Users\i92segoa\AppD
ata\LocalLow\Microsoft\CryptnetUrlCache\MetaData\5080DC7A65DB6A5960ECD874088F332
8_2908F682DFC81A793BD240CF29711C77"
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtReadFile, status:0x0, iostatu
s:0x0, information:0x124, length:0x124, handle:0x670, path:"C:\Users\i92segoa\Ap
pData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\5080DC7A65DB6A5960ECD874088F3
328_2908F682DFC81A793BD240CF29711C77"
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtReadFile, status:0x0, iostatu
s:0x0, information:0x2D7, length:0x2D7, handle:0x5F4, path:"C:\Users\i92segoa\Ap
pData\LocalLow\Microsoft\CryptnetUrlCache\Content\5080DC7A65DB6A5960ECD874088F33
28_2908F682DFC81A793BD240CF29711C77"
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtClose, status:0x0, handle:0x5
F4
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtClose, status:0x0, handle:0x6
70
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x77870000
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, iostatus:0x0, information:0xE0, code:0x390402, inlen:0x40, outlen:0x180, han
dle:0x340, path:"\Device\KsecDD"
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74AB0000, name:"GetHashInterface", ordinal:0x0, address:0
x74AC98C0, image:0x0, caller:0x72B3146B
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x670, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptography\
OID"
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x0, class:0x0, length:0x120, resultlength:0x2C, handle:0x670, path:"\REGISTR
Y\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID"
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x5F4, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\C
ryptography\OID\EncodingType 0"
pid:4092, tid:1488, tick:0x33D72AF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Micro
soft\Cryptography\OID\EncodingType 0\CryptDllVerifyEncodedSignature"
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtClose, status:0x0, handle:0x5
F4
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1, class:0x0, length:0x120, resultlength:0x2C, handle:0x670, path:"\REGISTR
Y\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID"
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x5F4, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\C
ryptography\OID\EncodingType 1"
pid:4092, tid:1488, tick:0x33D72AF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Micro
soft\Cryptography\OID\EncodingType 1\CryptDllVerifyEncodedSignature"
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtClose, status:0x0, handle:0x5
F4
pid:4092, tid:1488, tick:0x33D72AF, lvl:LOG, func:NtEnumerateKey, status:0x80000
01A, index:0x2, class:0x0, length:0x120, resultlength:0x0, handle:0x670, path:"\
REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID"
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtClose, status:0x0, handle:0x6
70
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x670, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptography\

OID"
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x0, class:0x0, length:0x120, resultlength:0x2C, handle:0x670, path:"\REGISTR
Y\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID"
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x5F4, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\C
ryptography\OID\EncodingType 0"
pid:4092, tid:1488, tick:0x33D72AF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Micro
soft\Cryptography\OID\EncodingType 0\CryptDllImportPublicKeyInfoEx2"
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtClose, status:0x0, handle:0x5
F4
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1, class:0x0, length:0x120, resultlength:0x2C, handle:0x670, path:"\REGISTR
Y\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID"
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x5F4, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\C
ryptography\OID\EncodingType 1"
pid:4092, tid:1488, tick:0x33D72AF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Micro
soft\Cryptography\OID\EncodingType 1\CryptDllImportPublicKeyInfoEx2"
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtClose, status:0x0, handle:0x5
F4
pid:4092, tid:1488, tick:0x33D72AF, lvl:LOG, func:NtEnumerateKey, status:0x80000
01A, index:0x2, class:0x0, length:0x120, resultlength:0x0, handle:0x670, path:"\
REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID"
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtClose, status:0x0, handle:0x6
70
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, iostatus:0x0, information:0x118, code:0x390402, inlen:0x38, outlen:0x180, ha
ndle:0x340, path:"\Device\KsecDD"
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74AB0000, name:"GetAsymmetricEncryptionInterface", ordina
l:0x0, address:0x74ADC770, image:0x0, caller:0x72B3146B
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x6E0, access:0x20119, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptography\
OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config"
pid:4092, tid:1488, tick:0x33D72AF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"CryptnetPreFetchMinMaxAgeSeconds", class:0x2, length:0x90, resultlen
gth:0x0, handle:0x6E0, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Cryptography\O
ID\EncodingType 0\CertDllCreateCertificateChainEngine\Config"
pid:4092, tid:1488, tick:0x33D72AF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"CryptnetPreFetchMaxMaxAgeSeconds", class:0x2, length:0x90, resultlen
gth:0x0, handle:0x6E0, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Cryptography\O
ID\EncodingType 0\CertDllCreateCertificateChainEngine\Config"
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtClose, status:0x0, handle:0x6
E0
pid:4092, tid:8264, tick:0x33D72AF, lvl:OK, func:NtWaitForMultipleObjects, statu
s:0x0, count:0x2, type:0x1, alertable:0x0, objects:0x6D8;0x6D4
pid:4092, tid:8264, tick:0x33D72AF, lvl:OK, func:NtClose, status:0x0, handle:0x6
D8
pid:4092, tid:8264, tick:0x33D72AF, lvl:OK, func:NtClose, status:0x0, handle:0x6
D4
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x6E0, access:0x20119, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptography\
OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config"
pid:4092, tid:1488, tick:0x33D72AF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"CryptnetCachedOcspSwitchToCrlCount", class:0x2, length:0x90, resultl
ength:0x0, handle:0x6E0, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Cryptography
\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config"

pid:4092, tid:1488, tick:0x33D72AF, lvl:LOG, func:NtQueryValueKey, status:0xC000


0034, name:"CryptnetMaxCachedOcspPerCrlCount", class:0x2, length:0x90, resultlen
gth:0x0, handle:0x6E0, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Cryptography\O
ID\EncodingType 0\CertDllCreateCertificateChainEngine\Config"
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtClose, status:0x0, handle:0x6
E0
pid:4092, tid:1488, tick:0x33D72AF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies\Microsof
t\SystemCertificates\ChainEngine\Config"
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtClose, status:0x0, handle:0x6
E4
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtClose, status:0x0, handle:0x6
E0
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x6E0, c
lass:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x6E4, c
lass:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x6E8, c
lass:0x1, length:0xC8, returnlength:0x24, sid:"S-1-5-21-2360094602-2602383397-24
63990887-1001", attributes:0x0
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtClose, status:0x0, handle:0x6
E8
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x6E8, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folder
s"
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Local AppData", class:0x2, length:0x90, resultlength:0x44, handle:0x6E8, pat
h:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Micros
oft\Windows\CurrentVersion\Explorer\User Shell Folders"
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Local AppData", class:0x2, length:0x90, resultlength:0x44, handle:0x6E8, pat
h:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Micros
oft\Windows\CurrentVersion\Explorer\User Shell Folders"
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x6EC, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows NT\Cu
rrentVersion\ProfileList\S-1-5-21-2360094602-2602383397-2463990887-1001"
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ProfileImagePath", class:0x2, length:0x90, resultlength:0x30, handle:0x6EC,
path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\ProfileList
\S-1-5-21-2360094602-2602383397-2463990887-1001"
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ProfileImagePath", class:0x2, length:0x90, resultlength:0x30, handle:0x6EC,
path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\ProfileList
\S-1-5-21-2360094602-2602383397-2463990887-1001"
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtClose, status:0x0, handle:0x6
EC
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtClose, status:0x0, handle:0x6
E8
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtClose, status:0x0, handle:0x6
E4
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x2010, path:"C:\Users\i92segoa\AppData\LocalLow"
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtOpenFile, status:0x0, handle:
0x6E8, access:0x20000, iostatus:0x0, information:0x1, share:0x7, options:0x20000
0, path:"C:\Users\i92segoa\AppData\LocalLow"
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtQuerySecurityObject, status:0

x0, class:0x10, length:0x400, requiredlength:0x30, handle:0x6E8, path:"C:\Users\


i92segoa\AppData\LocalLow"
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtClose, status:0x0, handle:0x6
E8
pid:4092, tid:1488, tick:0x33D72BE, lvl:OK, func:NtClose, status:0x0, handle:0x6
E0
pid:4092, tid:1488, tick:0x33D72BE, lvl:OK, func:NtOpenFile, status:0x0, handle:
0x6E0, access:0x100001, iostatus:0x0, information:0x0, share:0x7, options:0x4021
, path:"C:\Users\i92segoa\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\"
pid:4092, tid:1488, tick:0x33D72BE, lvl:OK, func:NtQueryDirectoryFile, status:0x
0, iostatus:0x0, information:0xE0, length:0x268, class:0x3, single:0x1, mask:"02
4823B39FBEACCDB5C06426A8168E99_*", restart:0x0, handle:0x6E0, path:"C:\Users\i92
segoa\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData"
pid:4092, tid:1488, tick:0x33D72BE, lvl:OK, func:NtQueryDirectoryFile, status:0x
0, iostatus:0x0, information:0xE0, length:0x1000, class:0x3, single:0x0, restart
:0x0, handle:0x6E0, path:"C:\Users\i92segoa\AppData\LocalLow\Microsoft\CryptnetU
rlCache\MetaData"
pid:4092, tid:1488, tick:0x33D72BE, lvl:LOG, func:NtQueryDirectoryFile, status:0
x80000006, iostatus:0x80000006, information:0x0, length:0x1000, class:0x3, singl
e:0x0, restart:0x0, handle:0x6E0, path:"C:\Users\i92segoa\AppData\LocalLow\Micro
soft\CryptnetUrlCache\MetaData"
pid:4092, tid:1488, tick:0x33D72BE, lvl:OK, func:NtClose, status:0x0, handle:0x6
E0
pid:4092, tid:1488, tick:0x33D72BE, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20119, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptog
raphy\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\CrlPreFetch"
pid:4092, tid:1488, tick:0x33D72BE, lvl:OK, func:NtClose, status:0x0, handle:0x5
F4
pid:4092, tid:1488, tick:0x33D72BE, lvl:OK, func:NtClose, status:0x0, handle:0x6
70
pid:4092, tid:1488, tick:0x33D72BE, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x670, c
lass:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:1488, tick:0x33D72BE, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x5F4, c
lass:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:1488, tick:0x33D72BE, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x69C, c
lass:0x1, length:0xC8, returnlength:0x24, sid:"S-1-5-21-2360094602-2602383397-24
63990887-1001", attributes:0x0
pid:4092, tid:1488, tick:0x33D72BE, lvl:OK, func:NtClose, status:0x0, handle:0x6
9C
pid:4092, tid:1488, tick:0x33D72BE, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x69C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folder
s"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Local AppData", class:0x2, length:0x90, resultlength:0x44, handle:0x69C, pat
h:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Micros
oft\Windows\CurrentVersion\Explorer\User Shell Folders"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Local AppData", class:0x2, length:0x90, resultlength:0x44, handle:0x69C, pat
h:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Micros
oft\Windows\CurrentVersion\Explorer\User Shell Folders"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x6CC, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows NT\Cu
rrentVersion\ProfileList\S-1-5-21-2360094602-2602383397-2463990887-1001"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ProfileImagePath", class:0x2, length:0x90, resultlength:0x30, handle:0x6CC,
path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\ProfileList

\S-1-5-21-2360094602-2602383397-2463990887-1001"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ProfileImagePath", class:0x2, length:0x90, resultlength:0x30, handle:0x6CC,
path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\ProfileList
\S-1-5-21-2360094602-2602383397-2463990887-1001"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtClose, status:0x0, handle:0x6
CC
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtClose, status:0x0, handle:0x6
9C
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtClose, status:0x0, handle:0x5
F4
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x2010, path:"C:\Users\i92segoa\AppData\LocalLow"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtOpenFile, status:0x0, handle:
0x69C, access:0x20000, iostatus:0x0, information:0x1, share:0x7, options:0x20000
0, path:"C:\Users\i92segoa\AppData\LocalLow"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtQuerySecurityObject, status:0
x0, class:0x10, length:0x400, requiredlength:0x30, handle:0x69C, path:"C:\Users\
i92segoa\AppData\LocalLow"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtClose, status:0x0, handle:0x6
9C
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtClose, status:0x0, handle:0x6
70
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtCreateFile, status:0x0, handl
e:0x670, access:0x80100080, iostatus:0x0, information:0x1, attribs:0x80, share:0
x1, disposition:0x1, options:0x60, path:"C:\Users\i92segoa\AppData\LocalLow\Micr
osoft\CryptnetUrlCache\MetaData\024823B39FBEACCDB5C06426A8168E99_4EB65D2EF896F9A
30A10A7F798B64304"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtCreateFile, status:0x0, handl
e:0x6E0, access:0x80100080, iostatus:0x0, information:0x1, attribs:0x80, share:0
x1, disposition:0x1, options:0x60, path:"C:\Users\i92segoa\AppData\LocalLow\Micr
osoft\CryptnetUrlCache\Content\024823B39FBEACCDB5C06426A8168E99_4EB65D2EF896F9A3
0A10A7F798B64304"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtQueryInformationFile, status:
0x0, iostatus:0x0, information:0x18, length:0x18, class:0x5, handle:0x670, path:
"C:\Users\i92segoa\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\024823B3
9FBEACCDB5C06426A8168E99_4EB65D2EF896F9A30A10A7F798B64304"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtReadFile, status:0x0, iostatu
s:0x0, information:0x4, length:0x4, handle:0x670, path:"C:\Users\i92segoa\AppDat
a\LocalLow\Microsoft\CryptnetUrlCache\MetaData\024823B39FBEACCDB5C06426A8168E99_
4EB65D2EF896F9A30A10A7F798B64304"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtReadFile, status:0x0, iostatu
s:0x0, information:0x6C, length:0x6C, handle:0x670, path:"C:\Users\i92segoa\AppD
ata\LocalLow\Microsoft\CryptnetUrlCache\MetaData\024823B39FBEACCDB5C06426A8168E9
9_4EB65D2EF896F9A30A10A7F798B64304"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtReadFile, status:0x0, iostatu
s:0x0, information:0x124, length:0x124, handle:0x670, path:"C:\Users\i92segoa\Ap
pData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\024823B39FBEACCDB5C06426A8168
E99_4EB65D2EF896F9A30A10A7F798B64304"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtReadFile, status:0x0, iostatu
s:0x0, information:0x1D8, length:0x1D8, handle:0x6E0, path:"C:\Users\i92segoa\Ap
pData\LocalLow\Microsoft\CryptnetUrlCache\Content\024823B39FBEACCDB5C06426A8168E
99_4EB65D2EF896F9A30A10A7F798B64304"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtClose, status:0x0, handle:0x6
E0
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtClose, status:0x0, handle:0x6
70
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, iostatus:0x0, information:0xE0, code:0x390402, inlen:0x40, outlen:0x180, han
dle:0x340, path:"\Device\KsecDD"

pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:LdrGetProcedureAddressForCaller


, status:0x0, module:0x74AB0000, name:"GetHashInterface", ordinal:0x0, address:0
x74AC98C0, image:0x0, caller:0x72B3146B
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x77870000
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x670, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\Microsoft\Cryptography\
Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Type", class:0x2, length:0x90, resultlength:0x10, handle:0x670, path:"\REGIS
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Micros
oft Enhanced RSA and AES Cryptographic Provider"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Image Path", class:0x2, length:0x90, resultlength:0x4E, handle:0x670, path:"
\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\
Microsoft Enhanced RSA and AES Cryptographic Provider"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Image Path", class:0x2, length:0x90, resultlength:0x4E, handle:0x670, path:"
\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\
Microsoft Enhanced RSA and AES Cryptographic Provider"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Image Path", class:0x2, length:0x90, resultlength:0x4E, handle:0x670, path:"
\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\
Microsoft Enhanced RSA and AES Cryptographic Provider"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Image Path", class:0x2, length:0x90, resultlength:0x4E, handle:0x670, path:"
\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\
Microsoft Enhanced RSA and AES Cryptographic Provider"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"C:\WINDOWS\system32\rsaenh.dll", handle:0x705E0000
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPAcquireContext", ordinal:0x0, address:0
x705E4CA0, image:0x0, caller:0x706542D4
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPReleaseContext", ordinal:0x0, address:0
x705E8930, image:0x0, caller:0x706542D4
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPGenKey", ordinal:0x0, address:0x705E600
0, image:0x0, caller:0x706542D4
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPDeriveKey", ordinal:0x0, address:0x705F
ADE0, image:0x0, caller:0x706542D4
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPDestroyKey", ordinal:0x0, address:0x705
E6D30, image:0x0, caller:0x706542D4
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPSetKeyParam", ordinal:0x0, address:0x70
5FC7D0, image:0x0, caller:0x706542D4
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPGetKeyParam", ordinal:0x0, address:0x70
5E8800, image:0x0, caller:0x706542D4
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPExportKey", ordinal:0x0, address:0x705E
5B80, image:0x0, caller:0x706542D4
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPImportKey", ordinal:0x0, address:0x705E
7440, image:0x0, caller:0x706542D4
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPEncrypt", ordinal:0x0, address:0x705F98
E0, image:0x0, caller:0x706542D4

pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:LdrGetProcedureAddressForCaller


, status:0x0, module:0x705E0000, name:"CPDecrypt", ordinal:0x0, address:0x705E95
A0, image:0x0, caller:0x706542D4
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPCreateHash", ordinal:0x0, address:0x705
E8040, image:0x0, caller:0x706542D4
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPHashData", ordinal:0x0, address:0x705E6
A30, image:0x0, caller:0x706542D4
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPHashSessionKey", ordinal:0x0, address:0
x705FA650, image:0x0, caller:0x706542D4
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPDestroyHash", ordinal:0x0, address:0x70
5E5A30, image:0x0, caller:0x706542D4
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPSignHash", ordinal:0x0, address:0x705FF
0B0, image:0x0, caller:0x706542D4
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPVerifySignature", ordinal:0x0, address:
0x705E6290, image:0x0, caller:0x706542D4
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPGenRandom", ordinal:0x0, address:0x705E
8C10, image:0x0, caller:0x706542D4
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPGetUserKey", ordinal:0x0, address:0x705
EB040, image:0x0, caller:0x706542D4
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPSetProvParam", ordinal:0x0, address:0x7
05FD280, image:0x0, caller:0x706542D4
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPGetProvParam", ordinal:0x0, address:0x7
05FB820, image:0x0, caller:0x706542D4
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPSetHashParam", ordinal:0x0, address:0x7
05E6EC0, image:0x0, caller:0x706542D4
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPGetHashParam", ordinal:0x0, address:0x7
05E6550, image:0x0, caller:0x706542D4
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPDuplicateKey", ordinal:0x0, address:0x7
05FB620, image:0x0, caller:0x70654303
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPDuplicateHash", ordinal:0x0, address:0x
705FA4C0, image:0x0, caller:0x70654303
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x6E0, c
lass:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtClose, status:0x0, handle:0x6
E0
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x6E0, access:0x20119, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptography"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"MachineGuid", class:0x2, length:0x90, resultlength:0x56, handle:0x6E0, path:
"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Cryptography"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"MachineGuid", class:0x2, length:0x90, resultlength:0x56, handle:0x6E0, path:
"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Cryptography"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"MachineGuid", class:0x2, length:0x90, resultlength:0x56, handle:0x6E0, path:

"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Cryptography"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"MachineGuid", class:0x2, length:0x90, resultlength:0x56, handle:0x6E0, path:
"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Cryptography"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtClose, status:0x0, handle:0x6
E0
pid:4092, tid:1488, tick:0x33D72CE, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptog
raphy\Offload"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x6E0, c
lass:0x1, length:0x400, returnlength:0x24, sid:"S-1-5-21-2360094602-2602383397-2
463990887-1001", attributes:0x0
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtClose, status:0x0, handle:0x6
E0
pid:4092, tid:1488, tick:0x33D72CE, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptog
raphy\DESHashSessionKeyBackward"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtClose, status:0x0, handle:0x6
70
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x670, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptography\
OID"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x0, class:0x0, length:0x120, resultlength:0x2C, handle:0x670, path:"\REGISTR
Y\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x6E0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\C
ryptography\OID\EncodingType 0"
pid:4092, tid:1488, tick:0x33D72CE, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Micro
soft\Cryptography\OID\EncodingType 0\CryptDllImportPublicKeyInfoEx"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtClose, status:0x0, handle:0x6
E0
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1, class:0x0, length:0x120, resultlength:0x2C, handle:0x670, path:"\REGISTR
Y\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x6E0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\C
ryptography\OID\EncodingType 1"
pid:4092, tid:1488, tick:0x33D72CE, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Micro
soft\Cryptography\OID\EncodingType 1\CryptDllImportPublicKeyInfoEx"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtClose, status:0x0, handle:0x6
E0
pid:4092, tid:1488, tick:0x33D72CE, lvl:LOG, func:NtEnumerateKey, status:0x80000
01A, index:0x2, class:0x0, length:0x120, resultlength:0x0, handle:0x670, path:"\
REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtClose, status:0x0, handle:0x6
70
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x670, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptography\
OID"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x0, class:0x0, length:0x120, resultlength:0x2C, handle:0x670, path:"\REGISTR
Y\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x6E0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\C
ryptography\OID\EncodingType 0"
pid:4092, tid:1488, tick:0x33D72CE, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034

, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Micro


soft\Cryptography\OID\EncodingType 0\CryptDllConvertPublicKeyInfo"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtClose, status:0x0, handle:0x6
E0
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1, class:0x0, length:0x120, resultlength:0x2C, handle:0x670, path:"\REGISTR
Y\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x6E0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\C
ryptography\OID\EncodingType 1"
pid:4092, tid:1488, tick:0x33D72CE, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Micro
soft\Cryptography\OID\EncodingType 1\CryptDllConvertPublicKeyInfo"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtClose, status:0x0, handle:0x6
E0
pid:4092, tid:1488, tick:0x33D72CE, lvl:LOG, func:NtEnumerateKey, status:0x80000
01A, index:0x2, class:0x0, length:0x120, resultlength:0x0, handle:0x670, path:"\
REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtClose, status:0x0, handle:0x6
70
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74AB0000, name:"GetAsymmetricEncryptionInterface", ordina
l:0x0, address:0x74ADC770, image:0x0, caller:0x72B3146B
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x670, access:0x20119, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptography\
OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config"
pid:4092, tid:1488, tick:0x33D72CE, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"CryptnetPreFetchMinMaxAgeSeconds", class:0x2, length:0x90, resultlen
gth:0x0, handle:0x670, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Cryptography\O
ID\EncodingType 0\CertDllCreateCertificateChainEngine\Config"
pid:4092, tid:1488, tick:0x33D72CE, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"CryptnetPreFetchMaxMaxAgeSeconds", class:0x2, length:0x90, resultlen
gth:0x0, handle:0x670, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Cryptography\O
ID\EncodingType 0\CertDllCreateCertificateChainEngine\Config"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtClose, status:0x0, handle:0x6
70
pid:4092, tid:8264, tick:0x33D72CE, lvl:OK, func:NtWaitForMultipleObjects, statu
s:0x0, count:0x2, type:0x1, alertable:0x0, objects:0x6D8;0x6D4
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"cryptnet.dll", handle:0x60BF0000
pid:4092, tid:8264, tick:0x33D72CE, lvl:OK, func:NtClose, status:0x0, handle:0x6
D8
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x60BF0000, name:"I_CryptNetGetConnectivity", ordinal:0x0,
address:0x60BF6C60, image:0x0, caller:0x778C5BBB
pid:4092, tid:8264, tick:0x33D72CE, lvl:OK, func:NtClose, status:0x0, handle:0x6
D4
pid:4092, tid:8264, tick:0x33D72CE, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x2, module:"C:\WINDOWS\SYSTEM32\crypt32.dll", handle:0x77870000
pid:4092, tid:8264, tick:0x33D72CE, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x664, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptography\
OID"
pid:4092, tid:8264, tick:0x33D72CE, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x0, class:0x0, length:0x120, resultlength:0x2C, handle:0x664, path:"\REGISTR
Y\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID"
pid:4092, tid:8264, tick:0x33D72CE, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x5F4, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\C
ryptography\OID\EncodingType 0"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtClose, status:0x0, handle:0x6
E0

pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtClose, status:0x0, handle:0x6


70
pid:4092, tid:8264, tick:0x33D72CE, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Micro
soft\Cryptography\OID\EncodingType 0\CertDllVerifyCertificateChainPolicy"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x670, c
lass:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:8264, tick:0x33D72CE, lvl:OK, func:NtClose, status:0x0, handle:0x5
F4
pid:4092, tid:8264, tick:0x33D72CE, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1, class:0x0, length:0x120, resultlength:0x2C, handle:0x664, path:"\REGISTR
Y\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID"
pid:4092, tid:8264, tick:0x33D72CE, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x5F4, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\C
ryptography\OID\EncodingType 1"
pid:4092, tid:3336, tick:0x33D72CE, lvl:LOG, func:BaseThreadInitThunk, log:"New
thread started (via BaseThreadInitThunk) at address: 0x778A0640, parameter: 0x83
D720"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtClose, status:0x0, handle:0x6
70
pid:4092, tid:8264, tick:0x33D72CE, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Micro
soft\Cryptography\OID\EncodingType 1\CertDllVerifyCertificateChainPolicy"
pid:4092, tid:8264, tick:0x33D72CE, lvl:OK, func:NtClose, status:0x0, handle:0x5
F4
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x60BF0000
pid:4092, tid:8264, tick:0x33D72CE, lvl:LOG, func:NtEnumerateKey, status:0x80000
01A, index:0x2, class:0x0, length:0x120, resultlength:0x0, handle:0x664, path:"\
REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x670, iostatus:0x0, information:0x68, code:0x12000F, inlen:0x38, outl
en:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:8264, tick:0x33D72CE, lvl:OK, func:NtClose, status:0x0, handle:0x6
64
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtClose, status:0x0, handle:0x6
70
pid:4092, tid:8264, tick:0x33D72CE, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x664, access:0x20119, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptography\
OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config"
pid:4092, tid:8264, tick:0x33D72CE, lvl:OK, func:NtNotifyChangeKey, status:0x103
, event:0x5F4, iostatus:0x103, information:0x0, filter:0x10000004, watch:0x0, le
ngth:0x0, async:0x1, handle:0x664, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Cr
yptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config"
pid:4092, tid:8264, tick:0x33D72CE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x69C, iocompletion:0x660, handle:0x5F4
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x6BC, iocompletion:0x38, handle:0x6B4
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtClose, status:0x0, handle:0x6
70
pid:4092, tid:8264, tick:0x33D72CE, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies\Microsof
t\SystemCertificates\AuthRoot"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x670, iostatus:0x0, information:0x68, code:0x12000F, inlen:0x38, outl
en:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtClose, status:0x0, handle:0x6
70
pid:4092, tid:8264, tick:0x33D72CE, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034

, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies\Microsof


t\SystemCertificates\Root\ProtectedRoots"
pid:4092, tid:8264, tick:0x33D72CE, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies\Microsof
t\SystemCertificates\AuthRoot"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x6E0, iocompletion:0x38, handle:0x6B8
pid:4092, tid:8264, tick:0x33D72CE, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x6CC, access:0x20119, path:"\REGISTRY\MACHINE\Software\Microsoft\SystemCertifi
cates\AuthRoot\AutoUpdate"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtClose, status:0x0, handle:0x6
70
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x670, iostatus:0x0, information:0x68, code:0x12000F, inlen:0x38, outl
en:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:8264, tick:0x33D72CE, lvl:OK, func:NtNotifyChangeKey, status:0x103
, event:0x6B0, iostatus:0x103, information:0x0, filter:0x10000004, watch:0x0, le
ngth:0x0, async:0x1, handle:0x6CC, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Sy
stemCertificates\AuthRoot\AutoUpdate"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtClose, status:0x0, handle:0x6
70
pid:4092, tid:8264, tick:0x33D72CE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x694, iocompletion:0x660, handle:0x6B0
pid:4092, tid:8264, tick:0x33D72CE, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"PinRulesLogDir", class:0x2, length:0x90, resultlength:0x77D194B8, ha
ndle:0x664, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Cryptography\OID\Encoding
Type 0\CertDllCreateCertificateChainEngine\Config"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x670, iostatus:0x0, information:0x70, code:0x12001B, inlen:0x3C, outl
en:0x3C, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:8264, tick:0x33D72CE, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"PinRules", class:0x2, length:0x90, resultlength:0x77793613, handle:0
x664, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Cryptography\OID\EncodingType 0
\CertDllCreateCertificateChainEngine\Config"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtClose, status:0x0, handle:0x6
70
pid:4092, tid:8264, tick:0x33D72CE, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x688, access:0x20119, path:"\REGISTRY\MACHINE\Software\Microsoft\SystemCertifi
cates\AuthRoot\AutoUpdate"
pid:4092, tid:8264, tick:0x33D72CE, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"PinRulesLastSyncTime", class:0x2, length:0x90, resultlength:0x14, handle:0x6
88, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\SystemCertificates\AuthRoot\AutoU
pdate"
pid:4092, tid:8264, tick:0x33D72CE, lvl:OK, func:NtClose, status:0x0, handle:0x6
88
pid:4092, tid:8264, tick:0x33D72CE, lvl:OK, func:NtClose, status:0x0, handle:0x6
98
pid:4092, tid:8264, tick:0x33D72CE, lvl:OK, func:NtClose, status:0x0, handle:0x6
88
pid:4092, tid:8264, tick:0x33D72CE, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x688, c
lass:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:8264, tick:0x33D72CE, lvl:OK, func:NtClose, status:0x0, handle:0x6
88
pid:4092, tid:8264, tick:0x33D72CE, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x688, c
lass:0x1, length:0x100, returnlength:0x24, sid:"S-1-5-21-2360094602-2602383397-2
463990887-1001", attributes:0x0
pid:4092, tid:8264, tick:0x33D72CE, lvl:OK, func:NtClose, status:0x0, handle:0x6
88

pid:4092, tid:8264, tick:0x33D72CE, lvl:OK, func:NtOpenKeyEx, status:0x0, handle


:0x698, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001"
pid:4092, tid:8264, tick:0x33D72CE, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x6E4, access:0x20119, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\SystemCertificates\AuthRoot\AutoUpdate"
pid:4092, tid:8264, tick:0x33D72CE, lvl:OK, func:NtClose, status:0x0, handle:0x6
98
pid:4092, tid:8264, tick:0x33D72CE, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"PinRulesLastSyncTime", class:0x2, length:0x90, resultlength:0x124B9D
0, handle:0x6E4, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24639908871001\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdate"
pid:4092, tid:8264, tick:0x33D72CE, lvl:OK, func:NtClose, status:0x0, handle:0x6
E4
pid:4092, tid:8264, tick:0x33D72CE, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x6E4, access:0x20119, path:"\REGISTRY\MACHINE\Software\Microsoft\SystemCertifi
cates\AuthRoot\AutoUpdate"
pid:4092, tid:8264, tick:0x33D72CE, lvl:LOG, func:NtQueryValueKey, status:0x8000
0005, name:"PinRulesEncodedCtl", class:0x2, length:0x90, resultlength:0x489C, ha
ndle:0x6E4, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\SystemCertificates\AuthRo
ot\AutoUpdate"
pid:4092, tid:8264, tick:0x33D72CE, lvl:LOG, func:NtQueryValueKey, status:0x8000
0005, name:"PinRulesEncodedCtl", class:0x2, length:0x90, resultlength:0x489C, ha
ndle:0x6E4, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\SystemCertificates\AuthRo
ot\AutoUpdate"
pid:4092, tid:8264, tick:0x33D72CE, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"PinRulesEncodedCtl", class:0x2, length:0x489C, resultlength:0x489C, handle:0
x6E4, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\SystemCertificates\AuthRoot\Aut
oUpdate"
pid:4092, tid:8264, tick:0x33D72CE, lvl:OK, func:NtClose, status:0x0, handle:0x6
E4
pid:4092, tid:8264, tick:0x33D72DE, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, iostatus:0x0, information:0x7E, code:0x1201F, inlen:0x10, outlen:0x0, handle
:0x53C, path:"\Device\Afd\Endpoint"
pid:4092, tid:8264, tick:0x33D72DE, lvl:OK, func:NtDeviceIoControlFile, status:0
x103, iostatus:0x103, information:0x0, code:0x12017, inlen:0x10, outlen:0x0, han
dle:0x53C, path:"\Device\Afd\Endpoint"
pid:4092, tid:1488, tick:0x33D72DE, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x670, iostatus:0x0, information:0x70, code:0x12001B, inlen:0x3C, outl
en:0x3C, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:1488, tick:0x33D72DE, lvl:OK, func:NtClose, status:0x0, handle:0x6
70
pid:4092, tid:1488, tick:0x33D72DE, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x670, iostatus:0x390DA34, information:0x20, code:0x12000F, in
len:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:1488, tick:0x33D72DE, lvl:OK, func:NtClose, status:0x0, handle:0x6
70
pid:4092, tid:1488, tick:0x33D72DE, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x670, iostatus:0x0, information:0x68, code:0x12000F, inlen:0x38, outl
en:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:1488, tick:0x33D72DE, lvl:OK, func:NtClose, status:0x0, handle:0x6
70
pid:4092, tid:1488, tick:0x33D72DE, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x670, iostatus:0x390DC8C, information:0xC, code:0x12000F, inl
en:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:1488, tick:0x33D72DE, lvl:OK, func:NtClose, status:0x0, handle:0x6
70
pid:4092, tid:1488, tick:0x33D72DE, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x670, iostatus:0x0, information:0x68, code:0x12000F, inlen:0x38, outl
en:0x38, handle:0x2F4, path:"\??\Nsi"

pid:4092, tid:1488, tick:0x33D72DE, lvl:OK, func:NtClose, status:0x0, handle:0x6


70
pid:4092, tid:1488, tick:0x33D72DE, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x670, iostatus:0x390DEE4, information:0xC, code:0x12000F, inl
en:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:1488, tick:0x33D72DE, lvl:OK, func:NtClose, status:0x0, handle:0x6
70
pid:4092, tid:1488, tick:0x33D72DE, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x670, iostatus:0x0, information:0x68, code:0x12000F, inlen:0x38, outl
en:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:1488, tick:0x33D72DE, lvl:OK, func:NtClose, status:0x0, handle:0x6
70
pid:4092, tid:1488, tick:0x33D72DE, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x670, iostatus:0x390E13C, information:0xC, code:0x12000F, inl
en:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:1488, tick:0x33D72DE, lvl:OK, func:NtClose, status:0x0, handle:0x6
70
pid:4092, tid:1488, tick:0x33D72DE, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x670, iostatus:0x390E13C, information:0xC, code:0x12000F, inl
en:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:1488, tick:0x33D72DE, lvl:OK, func:NtClose, status:0x0, handle:0x6
70
pid:4092, tid:1488, tick:0x33D72DE, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x670, iostatus:0x390E394, information:0xC, code:0x12000F, inl
en:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:1488, tick:0x33D72DE, lvl:OK, func:NtClose, status:0x0, handle:0x6
70
pid:4092, tid:1488, tick:0x33D72DE, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x670, iostatus:0x390E394, information:0xC, code:0x12000F, inl
en:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:1488, tick:0x33D72DE, lvl:OK, func:NtClose, status:0x0, handle:0x6
70
pid:4092, tid:1488, tick:0x33D72DE, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x670, iostatus:0x390E5EC, information:0xC, code:0x12000F, inl
en:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:1488, tick:0x33D72DE, lvl:OK, func:NtClose, status:0x0, handle:0x6
70
pid:4092, tid:1488, tick:0x33D72DE, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x670, iostatus:0x390E5EC, information:0xC, code:0x12000F, inl
en:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:1488, tick:0x33D72DE, lvl:OK, func:NtClose, status:0x0, handle:0x6
70
pid:4092, tid:1488, tick:0x33D72DE, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x77870000
pid:4092, tid:1488, tick:0x33D72DE, lvl:OK, func:NtOpenEvent, status:0x0, handle
:0x670, access:0x100000, path:"\Sessions\1\BaseNamedObjects\Global\SvcctrlStartE
vent_A3752DX"
pid:4092, tid:1488, tick:0x33D72DE, lvl:OK, func:NtClose, status:0x0, handle:0x6
70
pid:4092, tid:1488, tick:0x33D72DE, lvl:OK, func:OpenSCManagerW, ret:0x83D900, g
le:0x0, desiredAccess:0x1
pid:4092, tid:1488, tick:0x33D72DE, lvl:OK, func:OpenServiceW, ret:0x83D9C8, gle
:0x0, SCManager:0x83D900, serviceName:"CryptSvc", desiredAccess:0x5
pid:4092, tid:1488, tick:0x33D72DE, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x77870000
pid:4092, tid:1488, tick:0x33D72DE, lvl:OK, func:QueryServiceConfigW, ret:0x1, g
le:0x0, service:0x83D9C8, serviceConfig:0x331F060, bufSize:0x400, bytesNeeded:0x
13A
pid:4092, tid:1488, tick:0x33D72DE, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x670, c

lass:0x1, length:0x200, returnlength:0x24, sid:"S-1-5-21-2360094602-2602383397-2


463990887-1001", attributes:0x0
pid:4092, tid:1488, tick:0x33D72DE, lvl:OK, func:NtClose, status:0x0, handle:0x6
70
pid:4092, tid:1488, tick:0x33D72DE, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x77870000
pid:4092, tid:1488, tick:0x33D72DE, lvl:OK, func:CloseServiceHandle, ret:0x1, gl
e:0x0, SCObject:0x83D9C8
pid:4092, tid:1488, tick:0x33D72DE, lvl:OK, func:CloseServiceHandle, ret:0x1, gl
e:0x0, SCObject:0x83D900
pid:4092, tid:1488, tick:0x33D72DE, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x77870000
pid:4092, tid:1488, tick:0x33D72DE, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:1488, tick:0x33D72DE, lvl:OK, func:NtClose, status:0x0, handle:0x5
90
pid:4092, tid:1488, tick:0x33D72DE, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, iostatus:0x0, information:0x7E, code:0x1201F, inlen:0x10, outlen:0x0, handle
:0x55C, path:"\Device\Afd\Endpoint"
pid:4092, tid:1488, tick:0x33D72DE, lvl:OK, func:NtDeviceIoControlFile, status:0
x103, iostatus:0x103, information:0x0, code:0x12017, inlen:0x10, outlen:0x0, han
dle:0x55C, path:"\Device\Afd\Endpoint"
pid:4092, tid:1488, tick:0x33D7389, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x6D390000
pid:4092, tid:1488, tick:0x33D7389, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, iostatus:0x0, information:0xC0, code:0x390402, inlen:0x70, outlen:0x200, han
dle:0x340, path:"\Device\KsecDD"
pid:4092, tid:1488, tick:0x33D7389, lvl:LOG, func:NtOpenSection, status:0xC00000
34, handle:0x0, access:0xF, path:"\KnownDlls32\ncryptsslp.dll"
pid:4092, tid:1488, tick:0x33D7389, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x20, path:"C:\WINDOWS\system32\ncryptsslp.dll"
pid:4092, tid:1488, tick:0x33D7389, lvl:OK, func:NtOpenFile, status:0x0, handle:
0x6EC, access:0x100021, iostatus:0x0, information:0x1, share:0x5, options:0x60,
path:"C:\WINDOWS\system32\ncryptsslp.dll"
pid:4092, tid:1488, tick:0x33D7389, lvl:OK, func:NtCreateSection, status:0x0, ha
ndle:0x6F0, access:0xF, pageattribs:0x10, sectionattribs:0x1000000, file:0x6EC
pid:4092, tid:1488, tick:0x33D7389, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x6D360000, zerobits:0x0, commitsize:0x0, viewsize:0x1A000, disposition
:0x1, type:0x800000, protect:0x4, handle:0x6F0, path:"C:\WINDOWS\system32\ncrypt
sslp.dll"
pid:4092, tid:1488, tick:0x33D7389, lvl:OK, func:NtClose, status:0x0, handle:0x6
F0
pid:4092, tid:1488, tick:0x33D7389, lvl:OK, func:NtClose, status:0x0, handle:0x6
EC
pid:4092, tid:1488, tick:0x33D7389, lvl:OK, func:NtCreateSemaphore, status:0x0,
handle:0x6F0, access:0x100003, initialcount:0x0, maxcount:0x7FFFFFFF
pid:4092, tid:1488, tick:0x33D7389, lvl:OK, func:NtCreateSemaphore, status:0x0,
handle:0x6F4, access:0x100003, initialcount:0x0, maxcount:0x7FFFFFFF
pid:4092, tid:1488, tick:0x33D7389, lvl:OK, func:NtCreateSemaphore, status:0x0,
handle:0x6F8, access:0x100003, initialcount:0x0, maxcount:0x7FFFFFFF
pid:4092, tid:1488, tick:0x33D7389, lvl:OK, func:NtCreateSemaphore, status:0x0,
handle:0x6FC, access:0x100003, initialcount:0x0, maxcount:0x7FFFFFFF
pid:4092, tid:1488, tick:0x33D7389, lvl:OK, func:NtCreateSemaphore, status:0x0,
handle:0x700, access:0x100003, initialcount:0x0, maxcount:0x7FFFFFFF
pid:4092, tid:1488, tick:0x33D7389, lvl:OK, func:NtCreateSemaphore, status:0x0,
handle:0x704, access:0x100003, initialcount:0x0, maxcount:0x7FFFFFFF
pid:4092, tid:1488, tick:0x33D7389, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"C:\WINDOWS\system32\ncryptsslp.dll", handle:0x6D360000
pid:4092, tid:1488, tick:0x33D7389, lvl:OK, func:LdrGetProcedureAddressForCaller

, status:0x0, module:0x6D360000, name:"GetSChannelInterface", ordinal:0x0, addre


ss:0x6D367600, image:0x0, caller:0x64B64FFA
pid:4092, tid:1488, tick:0x33D7389, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74AB0000, name:"GetHashInterface", ordinal:0x0, address:0
x74AC98C0, image:0x0, caller:0x72B3146B
pid:4092, tid:1488, tick:0x33D7389, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74AB0000, name:"GetHashInterface", ordinal:0x0, address:0
x74AC98C0, image:0x0, caller:0x72B3146B
pid:4092, tid:1488, tick:0x33D7399, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, iostatus:0x0, information:0xD8, code:0x390402, inlen:0x38, outlen:0x180, han
dle:0x340, path:"\Device\KsecDD"
pid:4092, tid:1488, tick:0x33D7399, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74AB0000, name:"GetHashInterface", ordinal:0x0, address:0
x74AC98C0, image:0x0, caller:0x72B3146B
pid:4092, tid:1488, tick:0x33D7399, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74AB0000, name:"GetHashInterface", ordinal:0x0, address:0
x74AC98C0, image:0x0, caller:0x72B3146B
pid:4092, tid:1488, tick:0x33D7399, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, iostatus:0x0, information:0x118, code:0x390402, inlen:0x38, outlen:0x180, ha
ndle:0x340, path:"\Device\KsecDD"
pid:4092, tid:1488, tick:0x33D7399, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74AB0000, name:"GetCipherInterface", ordinal:0x0, address
:0x74ADC530, image:0x0, caller:0x72B3146B
pid:4092, tid:8264, tick:0x33D7399, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, iostatus:0x0, information:0x118, code:0x390402, inlen:0x38, outlen:0x180, ha
ndle:0x340, path:"\Device\KsecDD"
pid:4092, tid:8264, tick:0x33D7399, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74AB0000, name:"GetCipherInterface", ordinal:0x0, address
:0x74ADC530, image:0x0, caller:0x72B3146B
pid:4092, tid:1488, tick:0x33D7399, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x50C, iostatus:0x0, information:0x0, code:0x12047, inlen:0xA4, outlen
:0x0, handle:0x53C, path:"\Device\Afd\Endpoint"
pid:4092, tid:1488, tick:0x33D7399, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x50C, iostatus:0x0, information:0x0, code:0x12047, inlen:0xA4, outlen
:0x0, handle:0x53C, path:"\Device\Afd\Endpoint"
pid:4092, tid:8264, tick:0x33D7399, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x514, iostatus:0x0, information:0x0, code:0x12047, inlen:0xA4, outlen
:0x0, handle:0x55C, path:"\Device\Afd\Endpoint"
pid:4092, tid:8264, tick:0x33D7399, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x514, iostatus:0x0, information:0x0, code:0x12047, inlen:0xA4, outlen
:0x0, handle:0x55C, path:"\Device\Afd\Endpoint"
pid:4092, tid:1488, tick:0x33D7399, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, iostatus:0x0, information:0x221, code:0x1201F, inlen:0x10, outlen:0x0, handl
e:0x53C, path:"\Device\Afd\Endpoint"
pid:4092, tid:8264, tick:0x33D7399, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, iostatus:0x0, information:0x221, code:0x1201F, inlen:0x10, outlen:0x0, handl
e:0x55C, path:"\Device\Afd\Endpoint"
pid:4092, tid:1488, tick:0x33D7399, lvl:OK, func:NtDeviceIoControlFile, status:0
x103, iostatus:0x103, information:0x0, code:0x12017, inlen:0x10, outlen:0x0, han
dle:0x53C, path:"\Device\Afd\Endpoint"
pid:4092, tid:8264, tick:0x33D7399, lvl:OK, func:NtDeviceIoControlFile, status:0
x103, iostatus:0x103, information:0x0, code:0x12017, inlen:0x10, outlen:0x0, han
dle:0x55C, path:"\Device\Afd\Endpoint"
pid:4092, tid:8264, tick:0x33D73B8, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33D73B8, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33D7464, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x514, iostatus:0x0, information:0x0, code:0x1203B, inlen:0x10, outlen

:0x0, handle:0x53C, path:"\Device\Afd\Endpoint"


pid:4092, tid:8264, tick:0x33D7464, lvl:WRN, func:NtDeviceIoControlFile, status:
0xC00000A3, event:0x514, iostatus:0x103, information:0x2, code:0x12017, inlen:0x
10, outlen:0x0, handle:0x53C, path:"\Device\Afd\Endpoint"
pid:4092, tid:8264, tick:0x33D7464, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x514, iostatus:0x0, information:0x0, code:0x1203B, inlen:0x10, outlen
:0x0, handle:0x53C, path:"\Device\Afd\Endpoint"
pid:4092, tid:9004, tick:0x33D7464, lvl:OK, func:NtClose, status:0x0, handle:0x4
50
pid:4092, tid:9004, tick:0x33D7464, lvl:OK, func:NtClose, status:0x0, handle:0x4
48
pid:4092, tid:9004, tick:0x33D7464, lvl:LOG, func:LdrShutdownThread, log:"Thread
terminating..."
pid:4092, tid:9004, tick:0x33D7464, lvl:OK, func:NtWaitForMultipleObjects, statu
s:0x1, count:0x2, type:0x1, alertable:0x0, objects:0x5C0;0x5D8
pid:4092, tid:9004, tick:0x33D7464, lvl:OK, func:NtClose, status:0x0, handle:0x3
5C
pid:4092, tid:9004, tick:0x33D7464, lvl:OK, func:NtClose, status:0x0, handle:0x3
50
pid:4092, tid:9004, tick:0x33D7464, lvl:LOG, func:LdrShutdownThread, log:"Thread
terminated successfully!"
pid:4092, tid:8264, tick:0x33D7474, lvl:OK, func:NtDeviceIoControlFile, status:0
x103, iostatus:0x103, information:0x0, code:0x12017, inlen:0x10, outlen:0x0, han
dle:0x55C, path:"\Device\Afd\Endpoint"
pid:4092, tid:4644, tick:0x33D7474, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x6DC, iostatus:0x0, information:0x0, code:0x1202B, inlen:0x10, outlen
:0x0, handle:0x55C, path:"\Device\Afd\Endpoint"
pid:4092, tid:4644, tick:0x33D7474, lvl:OK, func:NtClose, status:0x0, handle:0x5
5C
pid:4092, tid:4644, tick:0x33D7474, lvl:OK, func:NtDuplicateObject, status:0x0,
targethandle:0x674, access:0x0, inherit:0x0, options:0x2, handle:0xFFFFFFFE
pid:4092, tid:4644, tick:0x33D7474, lvl:OK, func:NtClose, status:0x0, handle:0x4
54
pid:4092, tid:4644, tick:0x33D7474, lvl:OK, func:NtClose, status:0x0, handle:0x4
4C
pid:4092, tid:4644, tick:0x33D7474, lvl:LOG, func:LdrShutdownThread, log:"Thread
terminating..."
pid:4092, tid:4644, tick:0x33D7474, lvl:OK, func:NtWaitForMultipleObjects, statu
s:0x1, count:0x2, type:0x1, alertable:0x0, objects:0x5C0;0x5D8
pid:4092, tid:4644, tick:0x33D7474, lvl:OK, func:NtClose, status:0x0, handle:0x6
DC
pid:4092, tid:4644, tick:0x33D7474, lvl:OK, func:NtClose, status:0x0, handle:0x3
8C
pid:4092, tid:4644, tick:0x33D7474, lvl:OK, func:NtClose, status:0x0, handle:0x6
74
pid:4092, tid:4644, tick:0x33D7474, lvl:OK, func:NtClose, status:0x0, handle:0x5
5C
pid:4092, tid:4644, tick:0x33D7474, lvl:LOG, func:LdrShutdownThread, log:"Thread
terminated successfully!"
pid:4092, tid:8264, tick:0x33D77A0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33D77A0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33D7B98, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33D7B98, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33D7F90, lvl:OK, func:NtAssociateWaitCompletionPacket

, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48


pid:4092, tid:8264, tick:0x33D7F90, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33D8387, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33D8387, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33D8423, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33D876F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33D876F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33D8B57, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33D8B57, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33D8F3F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33D8F3F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33D9327, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33D9327, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33D971F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33D971F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33D9B07, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33D9B07, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33D9EEF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33D9EEF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33DA2D7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33DA2D7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33DA6BF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33DA6BF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33DAAA7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33DAAA7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses

sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:3336, tick:0x33DAD66, lvl:OK, func:NtWaitForMultipleObjects, statu
s:0x102, count:0x1, type:0x1, alertable:0x0, timeout:0xFFFFFFFFF70F2E80, objects
:0x6D4
pid:4092, tid:8264, tick:0x33DAE8F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33DAE8F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33DB277, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33DB277, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33DB65F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33DB65F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33DBA47, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33DBA47, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33DBE2F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33DBE2F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33DC217, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33DC217, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33DC5FF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33DC5FF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33DC9E7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33DC9E7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33DCDCF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33DCDCF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33DD1B7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33DD1B7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33DD59F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33DD59F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33DD987, lvl:OK, func:NtAssociateWaitCompletionPacket

, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48


pid:4092, tid:8264, tick:0x33DD987, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33DDD6F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33DDD6F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33DE157, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33DE157, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33DE510, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33DE510, lvl:OK, func:NtClose, status:0x0, handle:0x3
1C
pid:4092, tid:8264, tick:0x33DE53F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33DE53F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:3336, tick:0x33DE7FE, lvl:OK, func:NtWaitForMultipleObjects, statu
s:0x102, count:0x1, type:0x1, alertable:0x0, timeout:0xFFFFFFFFF70F2E80, objects
:0x6D4
pid:4092, tid:3336, tick:0x33DE7FE, lvl:OK, func:LdrUnloadDll, status:0x0, handl
e:0x60BF0000
pid:4092, tid:3336, tick:0x33DE7FE, lvl:OK, func:NtClose, status:0x0, handle:0x6
D8
pid:4092, tid:3336, tick:0x33DE7FE, lvl:OK, func:NtClose, status:0x0, handle:0x6
D4
pid:4092, tid:3336, tick:0x33DE7FE, lvl:OK, func:LdrUnloadDll, status:0x0, handl
e:0x77870000
pid:4092, tid:3336, tick:0x33DE7FE, lvl:LOG, func:LdrShutdownThread, log:"Thread
terminating..."
pid:4092, tid:3336, tick:0x33DE7FE, lvl:OK, func:NtWaitForMultipleObjects, statu
s:0x1, count:0x2, type:0x1, alertable:0x0, objects:0x5C0;0x5D8
pid:4092, tid:3336, tick:0x33DE7FE, lvl:LOG, func:LdrShutdownThread, log:"Thread
terminated successfully!"
pid:4092, tid:8264, tick:0x33DE927, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33DE927, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33DECA1, lvl:OK, func:NtClose, status:0x0, handle:0x5
88
pid:4092, tid:8264, tick:0x33DED0F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33DED0F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33DF0F7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33DF0F7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33DF4DF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33DF4DF, lvl:OK, func:NtAssociateWaitCompletionPacket

, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses


sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33DF8C7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33DF8C7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33DFCAF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33DFCAF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33E0097, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33E0097, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33E048E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33E048E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33E0876, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33E0876, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33E0C5E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33E0C5E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33E1046, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33E1046, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33E142E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33E142E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33E1816, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33E1816, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33E1BFE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33E1BFE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33E1FE6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33E1FE6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33E23CE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33E23CE, lvl:OK, func:NtAssociateWaitCompletionPacket

, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses


sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33E27B6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33E27B6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33E2B9E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33E2B9E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33E2F86, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33E2F86, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33E336E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33E336E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33E3756, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33E3756, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33E3B3E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33E3B3E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33E3F26, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33E3F26, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33E430E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33E430E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33E46F6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33E46F6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33E4ADE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33E4ADE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33E4EC6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33E4EC6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33E52AE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33E52AE, lvl:OK, func:NtAssociateWaitCompletionPacket

, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses


sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33E5696, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33E5696, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33E5A40, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33E5A40, lvl:OK, func:NtClose, status:0x0, handle:0x6
70
pid:4092, tid:8264, tick:0x33E5A40, lvl:OK, func:NtClose, status:0x0, handle:0x4
EC
pid:4092, tid:8264, tick:0x33E5A40, lvl:OK, func:NtClose, status:0x0, handle:0x4
A8
pid:4092, tid:8264, tick:0x33E5A7E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33E5A7E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33E5E66, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33E5E66, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33E624E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33E624E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33E6636, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33E6636, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:13216, tick:0x33E67AD, lvl:OK, func:NtWaitForMultipleObjects, stat
us:0x0, count:0x1, type:0x1, alertable:0x0, objects:0x504
pid:4092, tid:13216, tick:0x33E67AD, lvl:OK, func:NtClose, status:0x0, handle:0x
504
pid:4092, tid:8264, tick:0x33E6A1E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33E6A1E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33E6E06, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33E6E06, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33E71EE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33E71EE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33E75D6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33E75D6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33E79BE, lvl:OK, func:NtAssociateWaitCompletionPacket

, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48


pid:4092, tid:8264, tick:0x33E79BE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33E7DA6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33E7DA6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33E818E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33E818E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33E8576, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33E8576, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33E895E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33E895E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33E8D46, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33E8D46, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33E913E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33E913E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33E9526, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33E9526, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33E990E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33E990E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33E9CF6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33E9CF6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33EA0DE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33EA0DE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33EA4C6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33EA4C6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33EA8AE, lvl:OK, func:NtAssociateWaitCompletionPacket

, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48


pid:4092, tid:8264, tick:0x33EA8AE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33EAC96, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33EAC96, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33EB07E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33EB07E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33EB466, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33EB466, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33EB84E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33EB84E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33EBC36, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33EBC36, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33EC01E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33EC01E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33EC406, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33EC406, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33EC7EE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33EC7EE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33ECBD6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33ECBD6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33ECFBE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33ECFBE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33ED3A6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33ED3A6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33ED78E, lvl:OK, func:NtAssociateWaitCompletionPacket

, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48


pid:4092, tid:8264, tick:0x33ED78E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33EDB76, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33EDB76, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33EDF5E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33EDF5E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33EE346, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33EE346, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33EE72E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33EE72E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33EEB16, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33EEB16, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33EEEFE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33EEEFE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33EF2E6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33EF2E6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33EF6CE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33EF6CE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33EFAB6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33EFAB6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33EFE9E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33EFE9E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33F0286, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33F0286, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33F066E, lvl:OK, func:NtAssociateWaitCompletionPacket

, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48


pid:4092, tid:8264, tick:0x33F066E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33F0A56, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33F0A56, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33F0E3E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33F0E3E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33F1236, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33F1236, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33F161E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33F161E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33F1A06, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33F1A06, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33F1DAF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33F1DAF, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x514, iostatus:0x0, information:0x0, code:0x1203B, inlen:0x10, outlen
:0x0, handle:0x53C, path:"\Device\Afd\Endpoint"
pid:4092, tid:8264, tick:0x33F1DAF, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x514, iostatus:0x0, information:0x1, code:0x12017, inlen:0x10, outlen
:0x0, handle:0x53C, path:"\Device\Afd\Endpoint"
pid:4092, tid:8264, tick:0x33F1DAF, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x514, iostatus:0x0, information:0x0, code:0x1203B, inlen:0x10, outlen
:0x0, handle:0x53C, path:"\Device\Afd\Endpoint"
pid:4092, tid:8264, tick:0x33F1DAF, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x514, iostatus:0x0, information:0x0, code:0x1202B, inlen:0x10, outlen
:0x0, handle:0x53C, path:"\Device\Afd\Endpoint"
pid:4092, tid:8264, tick:0x33F1DAF, lvl:OK, func:NtClose, status:0x0, handle:0x5
3C
pid:4092, tid:8264, tick:0x33F1DEE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33F1DEE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33F21D6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33F21D6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33F25BE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33F25BE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:8264, tick:0x33F29A6, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33F29A6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33F2D8E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33F2D8E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33F3176, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33F3176, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33F355E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33F355E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33F3946, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33F3946, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33F3D2E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33F3D2E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33F4116, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33F4116, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33F44BF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33F44BF, lvl:OK, func:LdrUnloadDll, status:0x0, handl
e:0x74760000
pid:4092, tid:1488, tick:0x33F44BF, lvl:OK, func:NtClose, status:0x0, handle:0x4
DC
pid:4092, tid:8264, tick:0x33F44BF, lvl:OK, func:NtClose, status:0x0, handle:0x4
D8
pid:4092, tid:8264, tick:0x33F44FE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33F44FE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33F48E6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33F48E6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33F4CDD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33F4CDD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:13216, tick:0x33F4F8D, lvl:OK, func:NtWaitForMultipleObjects, stat
us:0x1, count:0x2, type:0x1, alertable:0x1, objects:0x598;0x504

pid:4092, tid:13216, tick:0x33F4F8D, lvl:OK, func:NtClose, status:0x0, handle:0x


504
pid:4092, tid:13216, tick:0x33F4F8D, lvl:OK, func:NtClose, status:0x0, handle:0x
598
pid:4092, tid:13216, tick:0x33F4F8D, lvl:OK, func:LdrUnloadDll, status:0x0, hand
le:0x74DC0000
pid:4092, tid:13216, tick:0x33F4F8D, lvl:LOG, func:LdrShutdownThread, log:"Threa
d terminating..."
pid:4092, tid:13216, tick:0x33F4F8D, lvl:OK, func:NtWaitForMultipleObjects, stat
us:0x1, count:0x2, type:0x1, alertable:0x0, objects:0x5C0;0x5D8
pid:4092, tid:13216, tick:0x33F4F8D, lvl:OK, func:NtClose, status:0x0, handle:0x
580
pid:4092, tid:13216, tick:0x33F4F8D, lvl:OK, func:NtClose, status:0x0, handle:0x
584
pid:4092, tid:13216, tick:0x33F4F8D, lvl:LOG, func:LdrShutdownThread, log:"Threa
d terminated successfully!"
pid:4092, tid:8264, tick:0x33F50C5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33F50C5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33F54BD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33F54BD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33F58B5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33F58B5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33F5CAC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33F5CAC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33F6094, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33F6094, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33F647C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33F647C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33F6864, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33F6864, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33F6C5C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33F6C5C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33F7053, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33F7053, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses

sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33F743B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33F743B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33F7833, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33F7833, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33F7C1B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33F7C1B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33F8003, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33F8003, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33F83EB, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33F83EB, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33F87E3, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33F87E3, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33F8BCB, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33F8BCB, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33F8FB3, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33F8FB3, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33F93AA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33F93AA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33F9792, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33F9792, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33F9B8A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33F9B8A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33F9F82, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33F9F82, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses

sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33FA36A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33FA36A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33FA752, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33FA752, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33FAB49, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33FAB49, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33FAF41, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33FAF41, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33FB329, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33FB329, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33FB711, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33FB711, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x33FB9EF, lvl:OK, func:LdrUnloadDll, status:0x0, handl
e:0x74760000
pid:4092, tid:1488, tick:0x33FB9EF, lvl:OK, func:NtClose, status:0x0, handle:0x4
74
pid:4092, tid:1488, tick:0x33FBAF9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x33FBAF9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x33FBEF0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x33FBEF0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x33FC2D8, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x33FC2D8, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x33FC6D0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x33FC6D0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x33FCAC8, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x33FCAC8, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x33FCEB0, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x33FCEB0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x33FD2A7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x33FD2A7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x33FD68F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x33FD68F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x33FDA87, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x33FDA87, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x33FDE6F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x33FDE6F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x33FE257, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x33FE257, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x33FE64F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x33FE64F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x33FEA37, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x33FEA37, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x33FEE1F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x33FEE1F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x33FF207, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x33FF207, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x33FF5FE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x33FF5FE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x33FF9F6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x33FF9F6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x33FFDDE, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x33FFDDE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34001D5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34001D5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34005BD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34005BD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34009B5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34009B5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3400DAD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3400DAD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3401195, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3401195, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x340158C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x340158C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3401974, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3401974, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3401D6C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3401D6C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3402154, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3402154, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x340253C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x340253C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3402934, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3402934, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x3402D1C, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3402D1C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3402F1F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3402F1F, lvl:OK, func:LdrUnloadDll, status:0x0, handl
e:0x72360000
pid:4092, tid:1488, tick:0x3402F1F, lvl:OK, func:LdrUnloadDll, status:0x0, handl
e:0x74760000
pid:4092, tid:1488, tick:0x3403113, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3403113, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34034FB, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34034FB, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34038F3, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34038F3, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3403CDB, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3403CDB, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34040D2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34040D2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34044BA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34044BA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34048B2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34048B2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3404C9A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3404C9A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3405082, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3405082, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x340546A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x340546A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses

sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3405862, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3405862, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3405C4A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3405C4A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3406041, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3406041, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3406429, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3406429, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3406821, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3406821, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3406C09, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3406C09, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3407001, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3407001, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34073E9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34073E9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34077D1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34077D1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3407BB9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3407BB9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3407FB0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3407FB0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3408398, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3408398, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses

sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3408780, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3408780, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3408B78, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3408B78, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3408F60, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3408F60, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3409348, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3409348, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3409730, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3409730, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3409B27, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3409B27, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3409F0F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3409F0F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x340A2F7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x340A2F7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x340A6DF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x340A6DF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x340AAD7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x340AAD7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x340AEBF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x340AEBF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x340B2A7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x340B2A7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses

sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x340B69F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x340B69F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x340BA87, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x340BA87, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x340BE7E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x340BE7E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x340C276, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x340C276, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x340C65E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x340C65E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x340CA56, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x340CA56, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x340CB6F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x340CE3E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x340CE3E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x340D235, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x340D235, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x340D61D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x340D61D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x340DA05, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x340DA05, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x340DDFD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x340DDFD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x340E1E5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48

pid:4092, tid:1488, tick:0x340E1E5, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x340E5DC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x340E5DC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x340E9C4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x340E9C4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x340EDBC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x340EDBC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x340F1A4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x340F1A4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x340F58C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x340F58C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x340F974, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x340F974, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x340FD6C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x340FD6C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3410154, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3410154, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x341053C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x341053C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3410933, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3410933, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3410D1B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3410D1B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3411113, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48

pid:4092, tid:1488, tick:0x3411113, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x341150B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x341150B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3411902, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3411902, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3411CEA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3411CEA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34120E2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34120E2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34124D9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34124D9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34128C1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34128C1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3412CA9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3412CA9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34130A1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34130A1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3413489, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3413489, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3413881, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3413881, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3413C69, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3413C69, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3414060, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48

pid:4092, tid:1488, tick:0x3414060, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3414458, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3414458, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3414840, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3414840, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3414C28, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3414C28, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3415020, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3415020, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3415408, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3415408, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34157F0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34157F0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3415BE7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3415BE7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3415FCF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3415FCF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34163C7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34163C7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34167AF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34167AF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3416BA6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3416BA6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3416F8E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48

pid:4092, tid:1488, tick:0x3416F8E, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3417376, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3417376, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x341776E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x341776E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3417B66, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3417B66, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3417F4E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3417F4E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3418336, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3418336, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x341871E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x341871E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3418B15, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3418B15, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3418F0D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3418F0D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3419305, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3419305, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34196ED, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34196ED, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3419AD5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3419AD5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3419EBD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48

pid:4092, tid:1488, tick:0x3419EBD, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x341A2B4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x341A2B4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x341A69C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x341A69C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x341AA84, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x341AA84, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x341AE7C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x341AE7C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x341B273, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x341B273, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x341B65B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x341B65B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x341BA43, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x341BA43, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x341BE3B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x341BE3B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x341C233, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x341C233, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x341C61B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x341C61B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x341CA12, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x341CA12, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x341CDFA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48

pid:4092, tid:1488, tick:0x341CDFA, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x341D1E2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x341D1E2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x341D5CA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x341D5CA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x341D9B2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x341D9B2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x341DD9A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x341DD9A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x341E182, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x341E182, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x341E56A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x341E56A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x341E952, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x341E952, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x341ED3A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x341ED3A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x341F122, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x341F122, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x341F50A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x341F50A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x341F8F2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x341F8F2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x341FCDA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48

pid:4092, tid:1488, tick:0x341FCDA, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34200C2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34200C2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34204AA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34204AA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x342066F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3420892, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3420892, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3420C7A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3420C7A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3421062, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3421062, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x342144A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x342144A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3421832, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3421832, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3421C1A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3421C1A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3422002, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3422002, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34223EA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34223EA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34227D2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34227D2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x3422BBA, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3422BBA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3422FA2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3422FA2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x342339A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x342339A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3423782, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3423782, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3423B6A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3423B6A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3423F52, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3423F52, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x342433A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x342433A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3424722, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3424722, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3424B0A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3424B0A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3424EF2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3424EF2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34252DA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34252DA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34256C2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34256C2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x3425AAA, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3425AAA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3425E92, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3425E92, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x342627A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x342627A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3426662, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3426662, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3426A4A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3426A4A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3426E32, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3426E32, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x342721A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x342721A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3427602, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3427602, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34279EA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34279EA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3427DD2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3427DD2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34281BA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34281BA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34285A2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34285A2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x342898A, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x342898A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3428D72, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3428D72, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x342915A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x342915A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3429542, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3429542, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x342992A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x342992A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3429D12, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3429D12, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x342A10A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x342A10A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x342A4F2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x342A4F2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x342A8DA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x342A8DA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x342ACC2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x342ACC2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x342B0AA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x342B0AA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x342B492, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x342B492, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x342B87A, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x342B87A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x342BC62, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x342BC62, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x342C04A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x342C04A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x342C432, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x342C432, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x342C81A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x342C81A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x342CC02, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x342CC02, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x342CFEA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x342CFEA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x342D3D2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x342D3D2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x342D7BA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x342D7BA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x342DBA2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x342DBA2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x342DF8A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x342DF8A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x342E372, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x342E372, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x342E75A, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x342E75A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x342EB42, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x342EB42, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x342EF2A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x342EF2A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x342F312, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x342F312, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x342F6FA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x342F6FA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x342FAE2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x342FAE2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x342FECA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x342FECA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34302B2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34302B2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x343069A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x343069A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3430A82, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3430A82, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3430E6A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3430E6A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3431252, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3431252, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x343163A, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x343163A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3431A31, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3431A31, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3431E19, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3431E19, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3432201, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3432201, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34325E9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34325E9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34329D1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34329D1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3432DB9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3432DB9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34331A1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34331A1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3433589, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3433589, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3433971, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3433971, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3433D59, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3433D59, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3434141, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3434141, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x3434529, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3434529, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3434911, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3434911, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3434CF9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3434CF9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34350E1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34350E1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34354C9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34354C9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34358B1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34358B1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3435C99, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3435C99, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3436081, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3436081, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3436469, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3436469, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3436851, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3436851, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3436C39, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3436C39, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3437021, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3437021, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x3437409, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3437409, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34377F1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34377F1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3437BD9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3437BD9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3437FC1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3437FC1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34383A9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34383A9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3438791, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3438791, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3438B79, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3438B79, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3438F71, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3438F71, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3439359, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3439359, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3439741, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3439741, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3439B29, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3439B29, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3439F11, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3439F11, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x343A2F9, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x343A2F9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x343A6E1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x343A6E1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x343AAC9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x343AAC9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x343AEB1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x343AEB1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x343B299, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x343B299, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x343B681, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x343B681, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x343BA69, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x343BA69, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x343BE51, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x343BE51, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x343C239, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x343C239, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x343C621, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x343C621, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x343CA09, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x343CA09, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x343CDF1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x343CDF1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x343D1D9, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x343D1D9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x343D5C1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x343D5C1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x343D9A9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x343D9A9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x343DD91, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x343DD91, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x343E179, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x343E179, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x343E561, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x343E561, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x343E949, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x343E949, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x343ED31, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x343ED31, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x343F119, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x343F119, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x343F501, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x343F501, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x343F8E9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x343F8E9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x343FCD1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x343FCD1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x34400B9, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34400B9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34404A1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34404A1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3440889, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3440889, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3440C71, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3440C71, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3441059, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3441059, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3441441, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3441441, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3441838, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3441838, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3441C20, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3441C20, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3442008, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3442008, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34423F0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34423F0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34427D8, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34427D8, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3442BC0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3442BC0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x3442FA8, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3442FA8, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3443390, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3443390, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3443778, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3443778, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3443B60, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3443B60, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3443F48, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3443F48, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3444330, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3444330, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3444718, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3444718, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3444B00, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3444B00, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3444EE8, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3444EE8, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34452D0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34452D0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34456B8, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34456B8, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3445AA0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3445AA0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x3445E88, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3445E88, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3446270, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3446270, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3446658, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3446658, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3446A40, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3446A40, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3446E28, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3446E28, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3447210, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3447210, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34475F8, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34475F8, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34479E0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34479E0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3447DC8, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3447DC8, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34481C0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34481C0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34485A8, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34485A8, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3448990, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3448990, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x3448D78, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3448D78, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3449160, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3449160, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3449548, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3449548, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3449930, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3449930, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3449D18, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3449D18, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x344A100, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x344A100, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x344A4E8, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x344A4E8, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x344A8D0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x344A8D0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x344ACB8, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x344ACB8, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x344B0A0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x344B0A0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x344B488, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x344B488, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x344B870, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x344B870, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x344BC58, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x344BC58, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x344C040, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x344C040, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x344C428, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x344C428, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x344C810, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x344C810, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x344CBF8, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x344CBF8, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x344CFE0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x344CFE0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x344D3C8, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x344D3C8, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x344D7B0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x344D7B0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x344DB98, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x344DB98, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x344DF80, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x344DF80, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x344E368, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x344E368, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x344E750, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x344E750, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x344EB38, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x344EB38, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x344EF20, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x344EF20, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x344F308, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x344F308, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x344F6F0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x344F6F0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x344FAE8, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x344FAE8, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x344FED0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x344FED0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34502B8, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34502B8, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34506A0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34506A0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3450A88, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3450A88, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3450E70, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3450E70, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3451258, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3451258, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3451640, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3451640, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x3451A28, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3451A28, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3451E10, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3451E10, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34521F8, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34521F8, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34525E0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34525E0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34529C8, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34529C8, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3452DB0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3452DB0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3453198, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3453198, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3453580, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3453580, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3453968, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3453968, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3453D50, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3453D50, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3454138, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3454138, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3454520, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3454520, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x3454908, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3454908, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3454CF0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3454CF0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34550D8, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34550D8, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34554C0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34554C0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34558A8, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34558A8, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3455C90, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3455C90, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3456078, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3456078, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3456460, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3456460, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3456848, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3456848, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3456C30, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3456C30, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3457018, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3457018, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3457400, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3457400, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x34577E8, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34577E8, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3457BD0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3457BD0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3457FB8, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3457FB8, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34583A0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34583A0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3458788, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3458788, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3458B7F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3458B7F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3458F67, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3458F67, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x345934F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x345934F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3459737, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3459737, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3459B1F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3459B1F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3459F07, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3459F07, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x345A2EF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x345A2EF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x345A6D7, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x345A6D7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x345AABF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x345AABF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x345AEA7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x345AEA7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x345B28F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x345B28F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x345B677, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x345B677, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x345BA5F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x345BA5F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x345BE47, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x345BE47, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x345C22F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x345C22F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x345C617, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x345C617, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x345C9FF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x345C9FF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x345CDE7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x345CDE7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x345D1CF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x345D1CF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x345D5B7, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x345D5B7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x345D99F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x345D99F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x345DD87, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x345DD87, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x345E16F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x345E16F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x345E557, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x345E557, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x345E93F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x345E93F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x345ED27, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x345ED27, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x345F10F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x345F10F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x345F4F7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x345F4F7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x345F8DF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x345F8DF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x345FCC7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x345FCC7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34600AF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34600AF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x3460497, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3460497, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x346088F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x346088F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3460C77, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3460C77, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x346105F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x346105F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3461447, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3461447, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x346182F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x346182F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3461C17, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3461C17, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3461FFF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3461FFF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34623E7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34623E7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34627CF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34627CF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3462BB7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3462BB7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3462F9F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3462F9F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x3463387, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3463387, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x346376F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x346376F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3463B57, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3463B57, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3463F3F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3463F3F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3464327, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3464327, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x346470F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x346470F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3464AF7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3464AF7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3464EDF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3464EDF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34652C7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34652C7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34656AF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34656AF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3465A97, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3465A97, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3465E7F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3465E7F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x3466267, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3466267, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x346664F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x346664F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3466A37, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3466A37, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3466E1F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3466E1F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3467207, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3467207, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34675EF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34675EF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34679D7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34679D7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3467DBF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3467DBF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34681A7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34681A7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x346858F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x346858F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3468977, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3468977, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3468D6F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3468D6F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x3469157, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3469157, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x346953F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x346953F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3469927, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3469927, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3469D0F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3469D0F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x346A0F7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x346A0F7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x346A4DF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x346A4DF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x346A8C7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x346A8C7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x346ACAF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x346ACAF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x346B097, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x346B097, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x346B47F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x346B47F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x346B867, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x346B867, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x346BC4F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x346BC4F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x346C037, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x346C037, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x346C41F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x346C41F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x346C807, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x346C807, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x346CBEF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x346CBEF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x346CFD7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x346CFD7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x346D3BF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x346D3BF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x346D7A7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x346D7A7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x346DB8F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x346DB8F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x346DF77, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x346DF77, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x346E35F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x346E35F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x346E747, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x346E747, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x346EB2F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x346EB2F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x346EF17, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x346EF17, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x346F2FF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x346F2FF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x346F6E7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x346F6E7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x346FACF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x346FACF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x346FEB7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x346FEB7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x347029F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x347029F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3470687, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3470687, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3470A6F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3470A6F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3470E57, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3470E57, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x347123F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x347123F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3471627, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3471627, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3471A1E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3471A1E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x3471E06, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3471E06, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34721EE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34721EE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34725D6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34725D6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34729BE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34729BE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3472DA6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3472DA6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x347318E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x347318E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3473576, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3473576, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x347395E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x347395E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3473D46, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3473D46, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x347412E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x347412E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3474516, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3474516, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34748FE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34748FE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x3474CE6, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3474CE6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34750CE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34750CE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34754B6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34754B6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x347589E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x347589E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3475C86, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3475C86, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x347606E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x347606E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3476456, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3476456, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x347683E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x347683E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3476C26, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3476C26, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x347700E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x347700E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34773F6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34773F6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34777DE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34777DE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x3477BC6, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3477BC6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3477FAE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3477FAE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3478396, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3478396, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x347877E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x347877E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3478B66, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3478B66, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3478F4E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3478F4E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3479336, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3479336, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x347971E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x347971E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3479B06, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3479B06, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3479EEE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3479EEE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x347A2D6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x347A2D6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x347A6BE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x347A6BE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x347AAB6, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x347AAB6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x347AE9E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x347AE9E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x347B286, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x347B286, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x347B66E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x347B66E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x347BA56, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x347BA56, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x347BE3E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x347BE3E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x347C226, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x347C226, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x347C60E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x347C60E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x347C9F6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x347C9F6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x347CDDE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x347CDDE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x347D1C6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x347D1C6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x347D5AE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x347D5AE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x347D996, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x347D996, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x347DD7E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x347DD7E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x347E166, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x347E166, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x347E54E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x347E54E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x347E936, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x347E936, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x347ED1E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x347ED1E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x347F106, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x347F106, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x347F4EE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x347F4EE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x347F8D6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x347F8D6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x347FCBE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x347FCBE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34800A6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34800A6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x348048E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x348048E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x3480876, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3480876, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3480C5E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3480C5E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3481046, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3481046, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x348142E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x348142E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3481816, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3481816, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3481BFE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3481BFE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3481FE6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3481FE6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34823CE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34823CE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34827B6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34827B6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3482B9E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3482B9E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3482F86, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3482F86, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x348336E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x348336E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x3483756, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3483756, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3483B3E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3483B3E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3483F26, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3483F26, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x348430E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x348430E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34846F6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34846F6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3484ADE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3484ADE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3484ED5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3484ED5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34852BD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34852BD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34856A5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34856A5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3485A8D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3485A8D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3485E75, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3485E75, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x348625D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x348625D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x3486645, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3486645, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3486A2D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3486A2D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3486E15, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3486E15, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34871FD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34871FD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34875E5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34875E5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34879CD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34879CD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3487DB5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3487DB5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x348819D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x348819D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3488585, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3488585, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x348896D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x348896D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3488D55, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3488D55, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x348913D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x348913D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x3489525, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3489525, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x348990D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x348990D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3489CF5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3489CF5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x348A0DD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x348A0DD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x348A4C5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x348A4C5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x348A8AD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x348A8AD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x348AC95, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x348AC95, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x348B07D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x348B07D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x348B465, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x348B465, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x348B84D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x348B84D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x348BC35, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x348BC35, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x348C01D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x348C01D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x348C405, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x348C405, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x348C7ED, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x348C7ED, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x348CBD5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x348CBD5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x348CFBD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x348CFBD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x348D3A5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x348D3A5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x348D78D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x348D78D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x348DB75, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x348DB75, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x348DF5D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x348DF5D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x348E345, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x348E345, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x348E73D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x348E73D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x348EB25, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x348EB25, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x348EF0D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x348EF0D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x348F2F5, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x348F2F5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x348F6DD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x348F6DD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x348FAC5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x348FAC5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x348FEAD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x348FEAD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3490295, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3490295, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x349067D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x349067D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3490A65, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3490A65, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3490E4D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3490E4D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3491235, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3491235, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x349161D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x349161D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3491A05, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3491A05, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3491DED, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3491DED, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x34921D5, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34921D5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34925BD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34925BD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34929A5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34929A5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3492D8D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3492D8D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3493175, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3493175, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x349355D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x349355D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3493945, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3493945, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3493D2D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3493D2D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3494115, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3494115, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34944FD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34944FD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34948E5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34948E5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3494CCD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3494CCD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x34950B5, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34950B5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x349549D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x349549D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3495885, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3495885, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3495C6D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3495C6D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3496055, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3496055, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x349643D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x349643D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3496825, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3496825, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3496C0D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3496C0D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3496FF5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3496FF5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34973DD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34973DD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34977C5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34977C5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3497BAD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3497BAD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x3497FA5, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3497FA5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x349838D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x349838D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3498775, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3498775, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3498B5D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3498B5D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3498F45, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3498F45, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x349932D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x349932D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3499715, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3499715, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3499AFD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3499AFD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3499EE5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3499EE5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x349A2CD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x349A2CD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x349A6B5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x349A6B5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x349AA9D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x349AA9D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x349AE85, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x349AE85, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x349B26D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x349B26D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x349B655, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x349B655, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x349BA3D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x349BA3D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x349BE25, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x349BE25, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x349C20D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x349C20D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x349C5F5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x349C5F5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x349C9DD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x349C9DD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x349CDC5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x349CDC5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x349D1AD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x349D1AD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x349D595, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x349D595, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x349D97D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x349D97D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x349DD65, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x349DD65, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x349E14D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x349E14D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x349E535, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x349E535, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x349E91D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x349E91D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x349ED05, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x349ED05, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x349F0ED, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x349F0ED, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x349F4D5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x349F4D5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x349F8BD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x349F8BD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x349FCA5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x349FCA5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34A008D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34A008D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34A0475, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34A0475, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34A085D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34A085D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x34A0C54, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34A0C54, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34A103C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34A103C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34A1424, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34A1424, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34A180C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34A180C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34A1BF4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34A1BF4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34A1FDC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34A1FDC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34A23C4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34A23C4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34A27AC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34A27AC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34A2B94, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34A2B94, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34A2F7C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34A2F7C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34A3364, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34A3364, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34A374C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34A374C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x34A3B34, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34A3B34, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34A3F1C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34A3F1C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34A4304, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34A4304, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34A46EC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34A46EC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34A4AD4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34A4AD4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34A4EBC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34A4EBC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34A52A4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34A52A4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34A568C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34A568C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34A5A74, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34A5A74, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34A5E5C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34A5E5C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34A6244, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34A6244, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34A662C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34A662C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x34A6A14, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34A6A14, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34A6DFC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34A6DFC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34A71E4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34A71E4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34A75CC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34A75CC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34A79B4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34A79B4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34A7D9C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34A7D9C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34A8184, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34A8184, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34A856C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34A856C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34A8954, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34A8954, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34A8D3C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34A8D3C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34A9124, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34A9124, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34A950C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34A950C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x34A98F4, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34A98F4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34A9CDC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34A9CDC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34AA0C4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34AA0C4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34AA4BC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34AA4BC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34AA8A4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34AA8A4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34AAC8C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34AAC8C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34AB074, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34AB074, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34AB45C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34AB45C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34AB844, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34AB844, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34ABC2C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34ABC2C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34AC014, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34AC014, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34AC3FC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34AC3FC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x34AC7E4, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34AC7E4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34ACBCC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34ACBCC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34ACFB4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34ACFB4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34AD39C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34AD39C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34AD784, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34AD784, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34ADB6C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34ADB6C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34ADF54, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34ADF54, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34AE33C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34AE33C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34AE724, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34AE724, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34AEB0C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34AEB0C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34AEEF4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34AEEF4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34AF2DC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34AF2DC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x34AF6C4, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34AF6C4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34AFAAC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34AFAAC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34AFE94, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34AFE94, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34B027C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34B027C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34B0664, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34B0664, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34B0A4C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34B0A4C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34B0E34, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34B0E34, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34B121C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34B121C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34B1604, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34B1604, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34B19EC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34B19EC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34B1DD4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34B1DD4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34B21BC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34B21BC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x34B25A4, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34B25A4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34B298C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34B298C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34B2D84, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34B2D84, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34B316C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34B316C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34B3554, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34B3554, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34B393C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34B393C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34B3D24, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34B3D24, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34B410C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34B410C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34B44F4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34B44F4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34B48DC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34B48DC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34B4CC4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34B4CC4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34B50AC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34B50AC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x34B5494, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34B5494, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34B587C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34B587C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34B5C64, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34B5C64, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34B604C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34B604C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34B6434, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34B6434, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34B681C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34B681C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34B6C04, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34B6C04, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34B6FEC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34B6FEC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34B73D4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34B73D4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34B77BC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34B77BC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34B7BA4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34B7BA4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34B7F8C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34B7F8C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x34B8374, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34B8374, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34B875C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34B875C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34B8B44, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34B8B44, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34B8F2C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34B8F2C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34B9314, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34B9314, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34B96FC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34B96FC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34B9AE4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34B9AE4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34B9ECC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34B9ECC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34BA2B4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34BA2B4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34BA69C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34BA69C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34BAA84, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34BAA84, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34BAE6C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34BAE6C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x34BB254, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34BB254, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34BB64B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34BB64B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34BBA33, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34BBA33, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34BBE1B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34BBE1B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34BC203, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34BC203, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34BC5EB, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34BC5EB, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34BC9D3, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34BC9D3, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34BCDBB, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34BCDBB, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34BD1A3, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34BD1A3, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34BD58B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34BD58B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34BD973, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34BD973, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34BDD5B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34BDD5B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x34BE143, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34BE143, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34BE52B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34BE52B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34BE913, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34BE913, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34BECFB, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34BECFB, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34BF0E3, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34BF0E3, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34BF4CB, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34BF4CB, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34BF8B3, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34BF8B3, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34BFC9B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34BFC9B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34C0083, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34C0083, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34C046B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34C046B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34C0853, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34C0853, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34C0C3B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34C0C3B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x34C1023, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34C1023, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34C140B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34C140B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34C17F3, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34C17F3, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34C1BDB, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34C1BDB, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34C1FC3, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34C1FC3, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34C23AB, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34C23AB, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34C2793, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34C2793, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34C2B7B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34C2B7B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34C2F63, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34C2F63, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34C334B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34C334B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34C3733, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34C3733, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34C3B1B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34C3B1B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x34C3F03, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34C3F03, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34C42EB, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34C42EB, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34C46D3, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34C46D3, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34C4ABB, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34C4ABB, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34C4EB3, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34C4EB3, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34C529B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34C529B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34C5683, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34C5683, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34C5A6B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34C5A6B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34C5E53, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34C5E53, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34C623B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34C623B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34C6623, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34C6623, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34C6A0B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34C6A0B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x34C6DF3, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34C6DF3, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34C71DB, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34C71DB, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34C75C3, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34C75C3, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34C79AB, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34C79AB, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34C7D93, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34C7D93, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34C817B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34C817B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34C8563, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34C8563, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34C894B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34C894B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34C8D33, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34C8D33, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34C911B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34C911B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34C9503, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34C9503, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34C98EB, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34C98EB, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x34C9CD3, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34C9CD3, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34CA0BB, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34CA0BB, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34CA4A3, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34CA4A3, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34CA88B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34CA88B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34CAC73, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34CAC73, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34CB05B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34CB05B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34CB443, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34CB443, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34CB83A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34CB83A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34CBC22, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34CBC22, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34CC00A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34CC00A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34CC3F2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34CC3F2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34CC7DA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34CC7DA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x34CCBC2, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34CCBC2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34CCFAA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34CCFAA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34CD392, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34CD392, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34CD77A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34CD77A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34CDB62, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34CDB62, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34CDF4A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34CDF4A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34CE332, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34CE332, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34CE71A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34CE71A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34CEB02, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34CEB02, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34CEEEA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34CEEEA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34CF2D2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34CF2D2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34CF6BA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34CF6BA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x34CFAA2, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34CFAA2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34CFE8A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34CFE8A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34D0272, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34D0272, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34D065A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34D065A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34D0A42, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34D0A42, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34D0E2A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34D0E2A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34D1212, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34D1212, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34D15FA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34D15FA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34D19E2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34D19E2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34D1DCA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34D1DCA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34D21B2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34D21B2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34D259A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34D259A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x34D2982, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34D2982, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34D2D6A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34D2D6A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34D3152, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34D3152, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34D353A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34D353A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34D3932, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34D3932, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34D3D1A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34D3D1A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34D4102, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34D4102, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34D44EA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34D44EA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34D48D2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34D48D2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34D4CBA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34D4CBA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34D50A2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34D50A2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34D548A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34D548A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x34D5872, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34D5872, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34D5C5A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34D5C5A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34D6042, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34D6042, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34D642A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34D642A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34D6812, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34D6812, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34D6BFA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34D6BFA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34D6FE2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34D6FE2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34D73CA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34D73CA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34D77B2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34D77B2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34D7B9A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34D7B9A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34D7F82, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34D7F82, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34D836A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34D836A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x34D8752, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34D8752, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34D8B3A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34D8B3A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34D8F22, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34D8F22, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34D930A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34D930A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34D96F2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34D96F2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34D9ADA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34D9ADA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34D9EC2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34D9EC2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34DA2AA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34DA2AA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34DA692, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34DA692, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34DAA7A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34DAA7A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34DAE62, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34DAE62, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34DB24A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34DB24A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x34DB632, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34DB632, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34DBA1A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34DBA1A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34DBE02, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34DBE02, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34DC1FA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34DC1FA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34DC5E2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34DC5E2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34DC9CA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34DC9CA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34DCDB2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34DCDB2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34DD19A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34DD19A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34DD582, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34DD582, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34DD96A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34DD96A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34DDD52, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34DDD52, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34DE13A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34DE13A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x34DE522, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34DE522, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34DE90A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34DE90A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34DECF2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34DECF2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34DF0DA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34DF0DA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34DF4C2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34DF4C2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34DF8AA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34DF8AA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34DFC92, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34DFC92, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34E007A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34E007A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34E0462, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34E0462, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34E084A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34E084A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34E0C32, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34E0C32, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34E101A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34E101A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x34E1402, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34E1402, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34E17EA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34E17EA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34E1BD2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34E1BD2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34E1FBA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34E1FBA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34E23A2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34E23A2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34E278A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34E278A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34E2B72, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34E2B72, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34E2F5A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34E2F5A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34E3342, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34E3342, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34E372A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34E372A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34E3B12, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34E3B12, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34E3F09, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34E3F09, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x34E42F1, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34E42F1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34E46D9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34E46D9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34E4AC1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34E4AC1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34E4EA9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34E4EA9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34E5291, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34E5291, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34E5679, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34E5679, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34E5A61, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34E5A61, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34E5E49, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34E5E49, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34E6231, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34E6231, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34E6619, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34E6619, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34E6A01, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34E6A01, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34E6DE9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34E6DE9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x34E71D1, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34E71D1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34E75B9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34E75B9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34E79A1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34E79A1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34E7D89, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34E7D89, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34E8171, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34E8171, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34E8559, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34E8559, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34E8941, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34E8941, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34E8D29, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34E8D29, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34E9111, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34E9111, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34E94F9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34E94F9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34E98E1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34E98E1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34E9CC9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34E9CC9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x34EA0B1, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34EA0B1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34EA499, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34EA499, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34EA881, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34EA881, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34EAC69, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34EAC69, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34EB051, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34EB051, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34EB439, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34EB439, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34EB821, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34EB821, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34EBC09, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34EBC09, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34EBFF1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34EBFF1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34EC3E9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34EC3E9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34EC7D1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34EC7D1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34ECBB9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34ECBB9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x34ECFA1, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34ECFA1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34ED389, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34ED389, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34ED771, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34ED771, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34EDB59, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34EDB59, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34EDF41, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34EDF41, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34EE329, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34EE329, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34EE711, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34EE711, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34EEAF9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34EEAF9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34EEEE1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34EEEE1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34EF2C9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34EF2C9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34EF6B1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34EF6B1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34EFA99, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34EFA99, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x34EFE81, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34EFE81, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34F0269, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34F0269, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34F0651, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34F0651, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34F0A39, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34F0A39, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34F0E21, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34F0E21, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34F1209, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34F1209, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34F15F1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34F15F1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34F19D9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34F19D9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34F1DC1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34F1DC1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34F21A9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34F21A9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34F2591, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34F2591, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34F2979, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34F2979, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x34F2D61, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34F2D61, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34F3149, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34F3149, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34F3531, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34F3531, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34F3929, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34F3929, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34F3D11, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34F3D11, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34F40F9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34F40F9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34F44E1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34F44E1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34F48C9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34F48C9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34F4CB1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34F4CB1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34F5099, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34F5099, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34F5481, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34F5481, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34F5869, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34F5869, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x34F5C51, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34F5C51, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34F6039, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34F6039, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34F6421, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34F6421, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34F6809, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34F6809, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34F6BF1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34F6BF1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34F6FD9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34F6FD9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34F73C1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34F73C1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34F77A9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34F77A9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34F7B91, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34F7B91, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34F7F79, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34F7F79, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34F8361, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34F8361, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34F8749, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34F8749, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:1488, tick:0x34F8B31, lvl:OK, func:NtAssociateWaitCompletionPacket


, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34F8B31, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x34F8D44, lvl:LOG, func:LdrShutdownThread, log:"Thread
terminating..."
pid:4092, tid:11200, tick:0x34F8D44, lvl:LOG, func:LdrShutdownThread, log:"Threa
d terminating..."
pid:4092, tid:556, tick:0x34F8D44, lvl:LOG, func:LdrShutdownThread, log:"Thread
terminating..."
pid:4092, tid:8800, tick:0x34F8D44, lvl:LOG, func:LdrShutdownThread, log:"Thread
terminating..."
pid:4092, tid:11200, tick:0x34F8D44, lvl:OK, func:NtWaitForMultipleObjects, stat
us:0x1, count:0x2, type:0x1, alertable:0x0, objects:0x5C0;0x5D8
pid:4092, tid:11200, tick:0x34F8D44, lvl:OK, func:NtClose, status:0x0, handle:0x
51C
pid:4092, tid:11200, tick:0x34F8D44, lvl:OK, func:NtClose, status:0x0, handle:0x
568
pid:4092, tid:11200, tick:0x34F8D44, lvl:OK, func:NtClose, status:0x0, handle:0x
4A4
pid:4092, tid:11200, tick:0x34F8D44, lvl:OK, func:NtClose, status:0x0, handle:0x
4A0
pid:4092, tid:8800, tick:0x34F8D44, lvl:OK, func:NtWaitForMultipleObjects, statu
s:0x1, count:0x2, type:0x1, alertable:0x0, objects:0x5C0;0x5D8
pid:4092, tid:11200, tick:0x34F8D44, lvl:LOG, func:LdrShutdownThread, log:"Threa
d terminated successfully!"
pid:4092, tid:8800, tick:0x34F8D44, lvl:OK, func:NtClose, status:0x0, handle:0x4
08
pid:4092, tid:8800, tick:0x34F8D44, lvl:OK, func:NtClose, status:0x0, handle:0x4
1C
pid:4092, tid:8800, tick:0x34F8D44, lvl:OK, func:NtClose, status:0x0, handle:0x4
68
pid:4092, tid:8800, tick:0x34F8D44, lvl:OK, func:NtClose, status:0x0, handle:0x4
5C
pid:4092, tid:8264, tick:0x34F8D44, lvl:OK, func:NtWaitForMultipleObjects, statu
s:0x1, count:0x2, type:0x1, alertable:0x0, objects:0x5C0;0x5D8
pid:4092, tid:8800, tick:0x34F8D44, lvl:LOG, func:LdrShutdownThread, log:"Thread
terminated successfully!"
pid:4092, tid:8264, tick:0x34F8D44, lvl:OK, func:NtClose, status:0x0, handle:0x5
14
pid:4092, tid:8264, tick:0x34F8D44, lvl:OK, func:NtClose, status:0x0, handle:0x4
D4
pid:4092, tid:8264, tick:0x34F8D44, lvl:OK, func:NtClose, status:0x0, handle:0x4
80
pid:4092, tid:8264, tick:0x34F8D44, lvl:OK, func:NtClose, status:0x0, handle:0x4
7C
pid:4092, tid:8264, tick:0x34F8D44, lvl:LOG, func:LdrShutdownThread, log:"Thread
terminated successfully!"
pid:4092, tid:556, tick:0x34F8D44, lvl:OK, func:NtWaitForMultipleObjects, status
:0x1, count:0x2, type:0x1, alertable:0x0, objects:0x5C0;0x5D8
pid:4092, tid:556, tick:0x34F8D44, lvl:OK, func:NtClose, status:0x0, handle:0x48
8
pid:4092, tid:556, tick:0x34F8D44, lvl:OK, func:NtClose, status:0x0, handle:0x48
4
pid:4092, tid:556, tick:0x34F8D44, lvl:LOG, func:LdrShutdownThread, log:"Thread
terminated successfully!"
pid:4092, tid:1488, tick:0x34F8F19, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34F8F19, lvl:OK, func:NtAssociateWaitCompletionPacket

, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses


sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x34F8F19, lvl:LOG, func:BaseThreadInitThunk, log:"New
thread started (via BaseThreadInitThunk) at address: 0x77C3C6D0, parameter: 0x7
652D8"
pid:4092, tid:12448, tick:0x34F9301, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x34F9301, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x34F96E9, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x34F96E9, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x34F9AD1, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x34F9AD1, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x34F9EB9, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x34F9EB9, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x34FA2A1, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x34FA2A1, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x34FA689, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x34FA689, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x34FAA71, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x34FAA71, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x34FAE59, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x34FAE59, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x34FB241, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x34FB241, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x34FB629, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x34FB629, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x34FBA11, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x34FBA11, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x34FBDF9, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x34FBDF9, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x34FC1E1, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x34FC1E1, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x34FC5C9, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x34FC5C9, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x34FC9B1, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x34FC9B1, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x34FCD99, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x34FCD99, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x34FD181, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x34FD181, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x34FD569, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x34FD569, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x34FD951, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x34FD951, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x34FDD48, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x34FDD48, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x34FE130, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x34FE130, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x34FE518, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x34FE518, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x34FE900, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x34FE900, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x34FECE8, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x34FECE8, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x34FF0D0, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x34FF0D0, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x34FF4B8, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x34FF4B8, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x34FF8A0, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x34FF8A0, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x34FFC88, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x34FFC88, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3500070, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3500070, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3500458, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3500458, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3500840, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3500840, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3500C28, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3500C28, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3501010, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3501010, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35013F8, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35013F8, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35017E0, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35017E0, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x3501BC8, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3501BC8, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3501FB0, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3501FB0, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3502398, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3502398, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3502780, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3502780, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3502B68, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3502B68, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3502F50, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3502F50, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3503338, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3503338, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3503720, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3503720, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3503B08, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3503B08, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3503EF0, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3503EF0, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35042D8, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35042D8, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35046C0, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35046C0, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x3504AA8, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3504AA8, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3504EA0, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3504EA0, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3505288, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3505288, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3505670, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3505670, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3505A58, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3505A58, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3505E40, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3505E40, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3506228, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3506228, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3506610, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3506610, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35069F8, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35069F8, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3506DE0, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3506DE0, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35071C8, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35071C8, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35075B0, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35075B0, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x3507998, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3507998, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3507D80, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3507D80, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3508168, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3508168, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3508550, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3508550, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3508938, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3508938, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3508D20, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3508D20, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3509108, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3509108, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35094F0, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35094F0, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35098D8, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35098D8, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3509CC0, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3509CC0, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x350A0A8, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x350A0A8, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x350A490, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x350A490, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x350A878, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x350A878, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x350AC60, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x350AC60, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x350B048, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x350B048, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x350B430, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x350B430, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x350B818, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x350B818, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x350BC00, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x350BC00, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x350BFE8, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x350BFE8, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x350C3D0, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x350C3D0, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x350C7B8, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x350C7B8, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x350CBA0, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x350CBA0, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x350CF88, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x350CF88, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x350D37F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x350D37F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x350D767, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x350D767, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x350DB4F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x350DB4F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x350DF37, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x350DF37, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x350E31F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x350E31F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x350E707, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x350E707, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x350EAEF, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x350EAEF, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x350EED7, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x350EED7, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x350F2BF, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x350F2BF, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x350F6A7, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x350F6A7, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x350FA8F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x350FA8F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x350FE77, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x350FE77, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x351025F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x351025F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x3510647, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3510647, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3510A2F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3510A2F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3510E17, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3510E17, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35111FF, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35111FF, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35115E7, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35115E7, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35119CF, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35119CF, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3511DB7, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3511DB7, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x351219F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x351219F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3512587, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3512587, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x351296F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x351296F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3512D57, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3512D57, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x351313F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x351313F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x3513527, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3513527, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x351390F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x351390F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3513CF7, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3513CF7, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35140DF, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35140DF, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35144D7, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35144D7, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35148BF, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35148BF, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3514CA7, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3514CA7, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x351508F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x351508F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3515477, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3515477, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x351585F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x351585F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3515C47, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3515C47, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x351602F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x351602F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x3516417, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3516417, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35167FF, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35167FF, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3516BE7, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3516BE7, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3516FCF, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3516FCF, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35173B7, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35173B7, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x351779F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x351779F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3517B87, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3517B87, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3517F6F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3517F6F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3518357, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3518357, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x351873F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x351873F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3518B27, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3518B27, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3518F0F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3518F0F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x35192F7, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35192F7, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35196DF, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35196DF, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3519AC7, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3519AC7, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3519EAF, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3519EAF, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x351A297, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x351A297, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x351A67F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x351A67F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x351AA67, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x351AA67, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x351AE4F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x351AE4F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x351B237, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x351B237, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x351B61F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x351B61F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x351BA07, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x351BA07, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x351BDEF, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x351BDEF, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x351C1D7, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x351C1D7, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x351C5BF, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x351C5BF, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x351C9A7, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x351C9A7, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x351CD8F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x351CD8F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x351D187, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x351D187, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x351D56F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x351D56F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x351D957, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x351D957, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x351DD3F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x351DD3F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x351E127, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x351E127, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x351E50F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x351E50F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x351E8F7, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x351E8F7, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x351ECDF, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x351ECDF, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x351F0C7, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x351F0C7, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x351F4AF, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x351F4AF, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x351F897, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x351F897, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x351FC7F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x351FC7F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3520067, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3520067, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x352044F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x352044F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3520837, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3520837, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3520C1F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3520C1F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3521007, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3521007, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35213EF, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35213EF, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35217D7, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35217D7, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3521BBF, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3521BBF, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x3521FA7, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3521FA7, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x352238F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x352238F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3522777, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3522777, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3522B5F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3522B5F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3522F47, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3522F47, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x352332F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x352332F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3523717, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3523717, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3523AFF, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3523AFF, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3523EE7, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3523EE7, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35242CF, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35242CF, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35246B7, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35246B7, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3524A9F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3524A9F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x3524E87, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3524E87, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x352526F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x352526F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3525657, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3525657, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3525A4E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3525A4E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3525E36, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3525E36, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x352621E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x352621E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3526606, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3526606, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35269EE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35269EE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3526DD6, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3526DD6, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35271BE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35271BE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35275A6, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35275A6, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x352798E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x352798E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x3527D76, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3527D76, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x352815E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x352815E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3528546, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3528546, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x352892E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x352892E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3528D16, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3528D16, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35290FE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35290FE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35294E6, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35294E6, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35298CE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35298CE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3529CB6, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3529CB6, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x352A09E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x352A09E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x352A486, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x352A486, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x352A86E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x352A86E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x352AC56, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x352AC56, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x352B03E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x352B03E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x352B426, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x352B426, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x352B80E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x352B80E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x352BBF6, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x352BBF6, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x352BFDE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x352BFDE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x352C3C6, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x352C3C6, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x352C7AE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x352C7AE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x352CB96, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x352CB96, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x352CF7E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x352CF7E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x352D366, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x352D366, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x352D74E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x352D74E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x352DB36, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x352DB36, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x352DF1E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x352DF1E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x352E306, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x352E306, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x352E6EE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x352E6EE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x352EAE6, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x352EAE6, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x352EECE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x352EECE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x352F2B6, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x352F2B6, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x352F69E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x352F69E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x352FA86, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x352FA86, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x352FE6E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x352FE6E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3530256, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3530256, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x353063E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x353063E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x3530A26, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3530A26, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3530E0E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3530E0E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35311F6, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35311F6, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35315DE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35315DE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35319C6, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35319C6, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3531DAE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3531DAE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3532196, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3532196, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x353257E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x353257E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3532966, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3532966, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3532D4E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3532D4E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3533136, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3533136, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x353351E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x353351E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x3533906, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3533906, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3533CEE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3533CEE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35340D6, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35340D6, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35344BE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35344BE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35348A6, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35348A6, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3534C8E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3534C8E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3535076, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3535076, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x353545E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x353545E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3535846, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3535846, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3535C2E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3535C2E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3536016, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3536016, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35363FE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35363FE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x35367E6, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35367E6, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3536BDE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3536BDE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3536FC6, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3536FC6, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35373AE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35373AE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3537796, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3537796, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3537B7E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3537B7E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3537F66, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3537F66, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x353834E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x353834E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3538736, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3538736, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3538B1E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3538B1E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3538F06, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3538F06, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35392EE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35392EE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x35396D6, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35396D6, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3539ABE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3539ABE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3539EA6, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3539EA6, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x353A28E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x353A28E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x353A676, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x353A676, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x353AA5E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x353AA5E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x353AE46, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x353AE46, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x353B22E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x353B22E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x353B616, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x353B616, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x353B9FE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x353B9FE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x353BDE6, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x353BDE6, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x353C1CE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x353C1CE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x353C5B6, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x353C5B6, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x353C99E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x353C99E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x353CD86, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x353CD86, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x353D16E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x353D16E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x353D556, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x353D556, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x353D93E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x353D93E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x353DD35, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x353DD35, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x353E11D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x353E11D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x353E505, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x353E505, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x353E8ED, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x353E8ED, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x353ECD5, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x353ECD5, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x353F0BD, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x353F0BD, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x353F4A5, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x353F4A5, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x353F88D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x353F88D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x353FC75, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x353FC75, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x354005D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x354005D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3540445, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3540445, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x354082D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x354082D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3540C15, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3540C15, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3540FFD, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3540FFD, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35413E5, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35413E5, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35417CD, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35417CD, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3541BB5, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3541BB5, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3541F9D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3541F9D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x3542385, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3542385, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x354276D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x354276D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3542B55, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3542B55, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3542F3D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3542F3D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3543325, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3543325, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x354370D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x354370D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3543AF5, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3543AF5, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3543EDD, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3543EDD, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35442C5, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35442C5, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35446AD, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35446AD, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3544A95, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3544A95, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3544E7D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3544E7D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x3545265, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3545265, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x354564D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x354564D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3545A35, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3545A35, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3545E1D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3545E1D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3546215, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3546215, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35465FD, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35465FD, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35469E5, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35469E5, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3546DCD, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3546DCD, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35471B5, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35471B5, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x354759D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x354759D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3547985, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3547985, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3547D6D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3547D6D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x3548155, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3548155, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x354853D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x354853D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3548925, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3548925, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3548D0D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3548D0D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35490F5, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35490F5, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35494DD, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35494DD, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35498C5, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35498C5, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3549CAD, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3549CAD, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x354A095, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x354A095, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x354A47D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x354A47D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x354A865, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x354A865, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x354AC4D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x354AC4D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x354B035, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x354B035, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x354B41D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x354B41D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x354B805, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x354B805, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x354BBED, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x354BBED, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x354BFD5, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x354BFD5, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x354C3BD, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x354C3BD, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x354C7A5, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x354C7A5, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x354CB8D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x354CB8D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x354CF84, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x354CF84, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x354D36C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x354D36C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x354D754, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x354D754, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x354DB3C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x354DB3C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x354DF24, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x354DF24, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x354E30C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x354E30C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x354E6F4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x354E6F4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x354EADC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x354EADC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x354EEC4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x354EEC4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x354F2AC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x354F2AC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x354F694, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x354F694, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x354FA7C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x354FA7C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x354FE64, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x354FE64, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x355024C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x355024C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3550634, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3550634, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3550A1C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3550A1C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x3550E04, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3550E04, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35511EC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35511EC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35515D4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35515D4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35519BC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35519BC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3551DA4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3551DA4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x355218C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x355218C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3552574, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3552574, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x355295C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x355295C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3552D44, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3552D44, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x355312C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x355312C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3553514, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3553514, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35538FC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35538FC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x3553CE4, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3553CE4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35540CC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35540CC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35544B4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35544B4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x355489C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x355489C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3554C94, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3554C94, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x355507C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x355507C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3555464, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3555464, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x355584C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x355584C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3555C34, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3555C34, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x355601C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x355601C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3556404, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3556404, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35567EC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35567EC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x3556BD4, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3556BD4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3556FBC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3556FBC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35573A4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35573A4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x355778C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x355778C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3557B74, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3557B74, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3557F5C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3557F5C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3558344, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3558344, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x355872C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x355872C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3558B14, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3558B14, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3558EFC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3558EFC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35592E4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35592E4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35596CC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35596CC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x3559AB4, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3559AB4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3559E9C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3559E9C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x355A284, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x355A284, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x355A66C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x355A66C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x355AA54, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x355AA54, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x355AE3C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x355AE3C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x355B224, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x355B224, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x355B60C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x355B60C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x355B9F4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x355B9F4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x355BDDC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x355BDDC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x355C1C4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x355C1C4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x355C5AC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x355C5AC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x355C994, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x355C994, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x355CD7C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x355CD7C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x355D174, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x355D174, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x355D55C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x355D55C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x355D944, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x355D944, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x355DD2C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x355DD2C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x355E114, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x355E114, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x355E4FC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x355E4FC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x355E8E4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x355E8E4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x355ECCC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x355ECCC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x355F0B4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x355F0B4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x355F49C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x355F49C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x355F884, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x355F884, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x355FC6C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x355FC6C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3560054, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3560054, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x356043C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x356043C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3560824, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3560824, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3560C0C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3560C0C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3560FF4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3560FF4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35613DC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35613DC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35617C4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35617C4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3561BAC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3561BAC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3561F94, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3561F94, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x356237C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x356237C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x3562764, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3562764, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3562B4C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3562B4C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3562F34, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3562F34, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x356331C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x356331C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3563704, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3563704, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3563AEC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3563AEC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3563ED4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3563ED4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35642BC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35642BC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35646A4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35646A4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3564A8C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3564A8C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3564E74, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3564E74, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x356526B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x356526B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x3565653, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3565653, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3565A3B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3565A3B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3565E23, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3565E23, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x356620B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x356620B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35665F3, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35665F3, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35669DB, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35669DB, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3566DC3, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3566DC3, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35671AB, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35671AB, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3567593, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3567593, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x356797B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x356797B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3567D63, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3567D63, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x356814B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x356814B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x3568533, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3568533, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x356891B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x356891B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3568D03, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3568D03, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35690EB, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35690EB, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35694D3, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35694D3, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35698BB, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35698BB, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3569CA3, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3569CA3, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x356A08B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x356A08B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x356A473, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x356A473, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x356A85B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x356A85B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x356AC43, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x356AC43, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x356B02B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x356B02B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x356B413, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x356B413, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x356B7FB, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x356B7FB, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x356BBE3, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x356BBE3, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x356BFCB, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x356BFCB, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x356C3B3, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x356C3B3, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x356C7AB, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x356C7AB, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x356CB93, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x356CB93, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x356CF7B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x356CF7B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x356D363, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x356D363, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x356D74B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x356D74B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x356DB33, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x356DB33, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x356DF1B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x356DF1B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x356E303, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x356E303, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x356E6EB, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x356E6EB, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x356EAD3, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x356EAD3, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x356EEBB, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x356EEBB, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x356F2A3, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x356F2A3, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x356F68B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x356F68B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x356FA73, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x356FA73, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x356FE5B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x356FE5B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3570243, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3570243, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x357062B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x357062B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3570A13, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3570A13, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3570DFB, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3570DFB, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x35711E3, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35711E3, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35715CB, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35715CB, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35719B3, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35719B3, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3571D9B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3571D9B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3572183, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3572183, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x357256B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x357256B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3572953, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3572953, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3572D3B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3572D3B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3573123, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3573123, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x357350B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x357350B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35738F3, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35738F3, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3573CDB, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3573CDB, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x35740C3, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35740C3, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35744AB, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35744AB, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3574893, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3574893, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3574C7B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3574C7B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3575063, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3575063, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x357544B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x357544B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3575833, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3575833, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3575C1B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3575C1B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3576013, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3576013, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35763FB, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35763FB, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35767E3, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35767E3, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3576BCB, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3576BCB, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x3576FB3, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3576FB3, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35773AA, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35773AA, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3577792, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3577792, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3577B7A, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3577B7A, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3577F62, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3577F62, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x357834A, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x357834A, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3578732, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3578732, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3578B1A, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3578B1A, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3578F12, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3578F12, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3579309, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3579309, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35796F1, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35796F1, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3579AD9, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3579AD9, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x3579EC1, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3579EC1, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x357A2B9, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x357A2B9, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x357A6A1, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x357A6A1, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x357AA99, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x357AA99, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x357AE81, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x357AE81, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x357B269, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x357B269, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x357B660, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x357B660, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x357BA48, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x357BA48, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x357BE30, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x357BE30, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x357C218, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x357C218, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x357C600, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x357C600, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x357C9E8, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x357C9E8, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x357CDE0, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x357CDE0, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x357D1C8, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x357D1C8, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x357D5B0, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x357D5B0, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x357D998, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x357D998, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x357DD80, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x357DD80, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x357E168, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x357E168, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x357E550, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x357E550, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x357E938, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x357E938, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x357ED20, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x357ED20, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x357F108, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x357F108, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x357F4F0, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x357F4F0, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x357F8D8, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x357F8D8, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x357FCC0, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x357FCC0, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35800A8, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35800A8, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3580490, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3580490, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3580878, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3580878, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3580C60, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3580C60, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3581058, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3581058, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3581440, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3581440, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3581828, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3581828, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3581C10, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3581C10, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3581FF8, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3581FF8, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35823E0, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35823E0, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35827C8, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35827C8, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x3582BB0, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3582BB0, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3582F98, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3582F98, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3583380, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3583380, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3583768, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3583768, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3583B5F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3583B5F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3583F47, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3583F47, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x358432F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x358432F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3584717, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3584717, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3584B0F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3584B0F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3584F06, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3584F06, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35852EE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35852EE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35856D6, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35856D6, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x3585ABE, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3585ABE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3585EA6, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3585EA6, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x358628E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x358628E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3586676, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3586676, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3586A6E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3586A6E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3586E56, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3586E56, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x358723E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x358723E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3587626, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3587626, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3587A0E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3587A0E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3587DF6, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3587DF6, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35881DE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35881DE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35885C6, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35885C6, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x35889AE, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35889AE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3588D96, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3588D96, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x358917E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x358917E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3589566, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3589566, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x358994E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x358994E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3589D36, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3589D36, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x358A11E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x358A11E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x358A506, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x358A506, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x358A8EE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x358A8EE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x358ACD6, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x358ACD6, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x358B0CE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x358B0CE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x358B4C5, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x358B4C5, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x358B8AD, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x358B8AD, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x358BC95, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x358BC95, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x358C08D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x358C08D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x358C475, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x358C475, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x358C85D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x358C85D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x358CC45, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x358CC45, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x358D02D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x358D02D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x358D415, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x358D415, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x358D7FD, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x358D7FD, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x358DBE5, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x358DBE5, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x358DFCD, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x358DFCD, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x358E3B5, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x358E3B5, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x358E79D, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x358E79D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x358EB85, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x358EB85, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x358EF6D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x358EF6D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x358F355, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x358F355, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x358F73D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x358F73D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x358FB25, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x358FB25, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x358FF0D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x358FF0D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35902F5, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35902F5, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35906ED, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35906ED, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3590AD5, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3590AD5, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3590EBD, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3590EBD, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35912A5, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35912A5, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x359168D, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x359168D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3591A75, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3591A75, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3591E5D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3591E5D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3592245, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3592245, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x359262D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x359262D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3592A15, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3592A15, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3592DFD, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3592DFD, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35931E5, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35931E5, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35935CD, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35935CD, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35939B5, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35939B5, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3593D9D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3593D9D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3594185, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3594185, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x359456D, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x359456D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3594955, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3594955, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3594D3D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3594D3D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3595125, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3595125, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x359551C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x359551C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3595904, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3595904, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3595CEC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3595CEC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35960D4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35960D4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35964BC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35964BC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35968A4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35968A4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3596C8C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3596C8C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3597074, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3597074, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x359745C, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x359745C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3597844, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3597844, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3597C2C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3597C2C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3598014, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3598014, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35983FC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35983FC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35987E4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35987E4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3598BCC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3598BCC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3598FB4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3598FB4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x359939C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x359939C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3599784, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3599784, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3599B6C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3599B6C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3599F54, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3599F54, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x359A33C, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x359A33C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x359A724, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x359A724, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x359AB0C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x359AB0C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x359AEF4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x359AEF4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x359B2DC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x359B2DC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x359B6D4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x359B6D4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x359BABC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x359BABC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x359BEA4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x359BEA4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x359C29B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x359C29B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x359C683, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x359C683, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x359CA6B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x359CA6B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x359CE53, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x359CE53, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x359D23B, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x359D23B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x359D623, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x359D623, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x359DA0B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x359DA0B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x359DDF3, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x359DDF3, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x359E1DB, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x359E1DB, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x359E5C3, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x359E5C3, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x359E9AB, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x359E9AB, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x359ED93, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x359ED93, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x359F17B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x359F17B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x359F563, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x359F563, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x359F94B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x359F94B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x359FD33, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x359FD33, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x35A011B, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35A011B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35A0503, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35A0503, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35A08EB, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35A08EB, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35A0CE3, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35A0CE3, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35A10CB, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35A10CB, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35A14B3, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35A14B3, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35A189B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35A189B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35A1C83, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35A1C83, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35A206B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35A206B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35A2453, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35A2453, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35A283B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35A283B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35A2C23, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35A2C23, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x35A300B, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35A300B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35A3403, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35A3403, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35A37EB, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35A37EB, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35A3BD3, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35A3BD3, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35A3FCA, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35A3FCA, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35A43B2, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35A43B2, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35A479A, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35A479A, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35A4B82, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35A4B82, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35A4F6A, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35A4F6A, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35A5352, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35A5352, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35A573A, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35A573A, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35A5B22, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35A5B22, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x35A5F0A, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35A5F0A, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35A62F2, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35A62F2, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35A66EA, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35A66EA, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35A6AD2, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35A6AD2, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35A6EBA, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35A6EBA, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35A72A2, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35A72A2, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35A768A, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35A768A, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35A7A72, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35A7A72, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35A7E5A, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35A7E5A, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35A8242, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35A8242, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35A862A, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35A862A, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35A8A12, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35A8A12, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x35A8DFA, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35A8DFA, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35A91E2, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35A91E2, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35A95CA, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35A95CA, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35A99B2, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35A99B2, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35A9D9A, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35A9D9A, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35AA192, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35AA192, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35AA57A, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35AA57A, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35AA962, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35AA962, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35AAD4A, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35AAD4A, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35AB132, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35AB132, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35AB51A, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35AB51A, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35AB902, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35AB902, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x35ABCEA, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35ABCEA, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35AC0D2, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35AC0D2, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35AC4BA, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35AC4BA, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35AC8A2, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35AC8A2, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35ACC8A, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35ACC8A, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35AD072, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35AD072, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35AD45A, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35AD45A, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35AD842, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35AD842, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35ADC2A, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35ADC2A, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35AE012, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35AE012, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35AE3FA, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35AE3FA, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35AE7E2, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35AE7E2, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x35AEBCA, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35AEBCA, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35AEFC1, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35AEFC1, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35AF3A9, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35AF3A9, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35AF791, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35AF791, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35AFB89, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35AFB89, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35AFF71, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35AFF71, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35B0359, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35B0359, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35B0741, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35B0741, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35B0B29, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35B0B29, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35B0F11, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35B0F11, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35B12F9, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35B12F9, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35B16E1, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35B16E1, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x35B1AC9, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35B1AC9, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35B1EB1, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35B1EB1, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35B22A8, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35B22A8, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35B2690, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35B2690, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35B2A78, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35B2A78, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35B2E60, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35B2E60, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35B3248, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35B3248, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35B3640, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35B3640, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35B3A28, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35B3A28, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35B3E10, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35B3E10, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35B41F8, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35B41F8, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35B45F0, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35B45F0, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x35B49D8, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35B49D8, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35B4DC0, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35B4DC0, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35B51B7, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35B51B7, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35B559F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35B559F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35B5987, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35B5987, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35B5D6F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35B5D6F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35B6157, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35B6157, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35B653F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35B653F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35B6927, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35B6927, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35B6D1F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35B6D1F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35B7107, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35B7107, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35B74EF, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35B74EF, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x35B78D7, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35B78D7, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35B7CBF, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35B7CBF, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35B80A7, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35B80A7, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35B848F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35B848F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35B8877, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35B8877, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35B8C5F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35B8C5F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35B9047, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35B9047, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35B942F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35B942F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35B9817, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35B9817, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35B9C0F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35B9C0F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35B9FF7, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35B9FF7, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35BA3DF, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35BA3DF, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x35BA7C7, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35BA7C7, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35BABAF, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35BABAF, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35BAF97, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35BAF97, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35BB37F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35BB37F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35BB767, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35BB767, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35BBB4F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35BBB4F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35BBF37, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35BBF37, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35BC31F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35BC31F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35BC707, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35BC707, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35BCAEF, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35BCAEF, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35BCEE6, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35BCEE6, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35BD2CE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35BD2CE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x35BD6B6, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35BD6B6, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35BDA9E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35BDA9E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35BDE96, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35BDE96, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35BE27E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35BE27E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35BE666, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35BE666, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35BEA4E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35BEA4E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35BEE36, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35BEE36, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35BF21E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35BF21E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35BF606, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35BF606, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35BF9EE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35BF9EE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35BFDE5, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35BFDE5, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35C01CD, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35C01CD, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x35C05B5, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35C05B5, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35C099D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35C099D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35C0D85, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35C0D85, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35C117D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35C117D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35C1565, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35C1565, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35C194D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35C194D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35C1D35, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35C1D35, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35C211D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35C211D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35C2505, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35C2505, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35C28ED, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35C28ED, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35C2CE5, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35C2CE5, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35C30CD, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35C30CD, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x35C34B5, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35C34B5, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35C389D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35C389D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35C3C85, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35C3C85, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35C406D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35C406D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35C4455, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35C4455, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35C483D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35C483D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35C4C25, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35C4C25, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35C500D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35C500D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35C53F5, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35C53F5, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35C57EC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35C57EC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35C5BD4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35C5BD4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35C5FBC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35C5FBC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x35C63A4, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35C63A4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35C678C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35C678C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35C6B74, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35C6B74, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35C6F5C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35C6F5C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35C7344, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35C7344, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35C772C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35C772C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35C7B14, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35C7B14, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35C7EFC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35C7EFC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35C82E4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35C82E4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35C86DC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35C86DC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35C8AC4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35C8AC4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35C8EAC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35C8EAC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x35C9294, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35C9294, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35C967C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35C967C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35C9A64, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35C9A64, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35C9E4C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35C9E4C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35CA234, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35CA234, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35CA61C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35CA61C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35CAA04, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35CAA04, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35CADEC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35CADEC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35CB1D4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35CB1D4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35CB5BC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35CB5BC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35CB9A4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35CB9A4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35CBD8C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35CBD8C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x35CC174, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35CC174, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35CC55C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35CC55C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35CC944, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35CC944, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35CCD2C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35CCD2C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35CD114, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35CD114, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35CD4FC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35CD4FC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35CD8E4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35CD8E4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35CDCCC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35CDCCC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35CE0B4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35CE0B4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35CE49C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35CE49C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35CE884, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35CE884, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35CEC6C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35CEC6C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x35CF054, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35CF054, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35CF43C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35CF43C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35CF824, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35CF824, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35CFC0C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35CFC0C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35CFFF4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35CFFF4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35D03DC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35D03DC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35D07C4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35D07C4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35D0BAC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35D0BAC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35D0F94, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35D0F94, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35D137C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35D137C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35D1764, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35D1764, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35D1B5C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35D1B5C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x35D1F44, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35D1F44, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35D232C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35D232C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35D2714, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35D2714, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35D2AFC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35D2AFC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35D2EE4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35D2EE4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35D32CC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35D32CC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35D36B4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35D36B4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35D3A9C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35D3A9C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35D3E84, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35D3E84, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35D426C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35D426C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35D4654, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35D4654, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35D4A3C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35D4A3C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x35D4E24, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35D4E24, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35D520C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35D520C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35D55F4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35D55F4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35D59DC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35D59DC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35D5DC4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35D5DC4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35D61AC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35D61AC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35D6594, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35D6594, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35D697C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35D697C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35D6D64, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35D6D64, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35D714C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35D714C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35D7534, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35D7534, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35D791C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35D791C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

pid:4092, tid:12448, tick:0x35D7D04, lvl:OK, func:NtAssociateWaitCompletionPacke


t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35D7D04, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35D7DAF, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35D7DAF, lvl:OK, func:NtOpenKeyEx, status:0x0, handl
e:0x484, access:0x20119, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptography
\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config"
pid:4092, tid:12448, tick:0x35D7DAF, lvl:LOG, func:NtQueryValueKey, status:0xC00
00034, name:"AutoFlags", class:0x2, length:0x90, resultlength:0x28038272, handle
:0x484, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Cryptography\OID\EncodingType
0\CertDllCreateCertificateChainEngine\Config"
pid:4092, tid:12448, tick:0x35D7DBF, lvl:OK, func:LdrGetProcedureAddressForCalle
r, status:0x0, module:0x60BF0000, name:"I_CryptNetAutoFlush", ordinal:0x0, addre
ss:0x60C08DA0, image:0x0, caller:0x77925CA0
pid:4092, tid:12448, tick:0x35D7DBF, lvl:OK, func:NtClose, status:0x0, handle:0x
484
pid:4092, tid:12448, tick:0x35D80EC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35D80EC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35D84D4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35D84D4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35D88BC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35D88BC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35D8CA4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35D8CA4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35D908C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35D908C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35D9474, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35D9474, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35D985C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35D985C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35D9C44, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35D9C44, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35DA02C, lvl:OK, func:NtAssociateWaitCompletionPacke

t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48


pid:4092, tid:12448, tick:0x35DA02C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35DA414, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35DA414, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35DA7FC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35DA7FC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35DABE4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35DABE4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35DAFCC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35DAFCC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35DB3B4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35DB3B4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35DB79C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35DB79C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35DBB84, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35DBB84, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35DBF6C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35DBF6C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35DC354, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35DC354, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35DC73C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35DC73C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35DCB33, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35DCB33, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35DCF1B, lvl:OK, func:NtAssociateWaitCompletionPacke

t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48


pid:4092, tid:12448, tick:0x35DCF1B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35DD303, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35DD303, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35DD6EB, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35DD6EB, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35DDAD3, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35DDAD3, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35DDEBB, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35DDEBB, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35DE2A3, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35DE2A3, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35DE68B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35DE68B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35DEA73, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35DEA73, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35DEE5B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35DEE5B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35DF243, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35DF243, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35DF62B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35DF62B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35DFA13, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35DFA13, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35DFDFB, lvl:OK, func:NtAssociateWaitCompletionPacke

t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48


pid:4092, tid:12448, tick:0x35DFDFB, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35E01E3, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35E01E3, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35E05CB, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35E05CB, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35E09B3, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35E09B3, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35E0D9B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35E0D9B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35E1183, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35E1183, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35E156B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35E156B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35E1953, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35E1953, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35E1D3B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35E1D3B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35E2123, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35E2123, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35E250B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35E250B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35E28F3, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35E28F3, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35E2CDB, lvl:OK, func:NtAssociateWaitCompletionPacke

t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48


pid:4092, tid:12448, tick:0x35E2CDB, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35E30C3, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35E30C3, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35E34AB, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35E34AB, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35E3893, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35E3893, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35E3C7B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35E3C7B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35E4063, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35E4063, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35E444B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35E444B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35E4833, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35E4833, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35E4C1B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35E4C1B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35E5003, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35E5003, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35E53EB, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35E53EB, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35E57E3, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35E57E3, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35E5BCB, lvl:OK, func:NtAssociateWaitCompletionPacke

t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48


pid:4092, tid:12448, tick:0x35E5BCB, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35E5FB3, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35E5FB3, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35E639B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35E639B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35E6783, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35E6783, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35E6B6B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35E6B6B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35E6F53, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35E6F53, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35E733B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35E733B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35E7723, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35E7723, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35E7B0B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35E7B0B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35E7EF3, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35E7EF3, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35E82DB, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35E82DB, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35E86C3, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35E86C3, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35E8AAB, lvl:OK, func:NtAssociateWaitCompletionPacke

t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48


pid:4092, tid:12448, tick:0x35E8AAB, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35E8E93, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35E8E93, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35E927B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35E927B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35E9663, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35E9663, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35E9A4B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35E9A4B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35E9E33, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35E9E33, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35EA21B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35EA21B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35EA603, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35EA603, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35EA9EB, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35EA9EB, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35EADD3, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35EADD3, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35EB1BB, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35EB1BB, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35EB5A3, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35EB5A3, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35EB98B, lvl:OK, func:NtAssociateWaitCompletionPacke

t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48


pid:4092, tid:12448, tick:0x35EB98B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35EBD73, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35EBD73, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35EC15B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35EC15B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35EC543, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35EC543, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35EC93A, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35EC93A, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35ECD22, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35ECD22, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35ED11A, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35ED11A, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35ED502, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35ED502, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35ED8EA, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35ED8EA, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35EDCD2, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35EDCD2, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35EE0CA, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35EE0CA, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35EE4B2, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35EE4B2, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35EE89A, lvl:OK, func:NtAssociateWaitCompletionPacke

t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48


pid:4092, tid:12448, tick:0x35EE89A, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35EEC91, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35EEC91, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35EF079, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35EF079, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35EF461, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35EF461, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35EF859, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35EF859, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35EFC41, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35EFC41, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35F0039, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35F0039, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35F0421, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35F0421, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35F0818, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35F0818, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35F0C00, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35F0C00, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35F0FF8, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35F0FF8, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35F13EF, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35F13EF, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35F17D7, lvl:OK, func:NtAssociateWaitCompletionPacke

t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48


pid:4092, tid:12448, tick:0x35F17D7, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35F1BBF, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35F1BBF, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35F1FA7, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35F1FA7, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35F239F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35F239F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35F2797, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35F2797, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35F2B7F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35F2B7F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35F2F67, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35F2F67, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35F335E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35F335E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35F3746, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35F3746, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35F3B2E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35F3B2E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35F3F16, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35F3F16, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35F430E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35F430E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35F46F6, lvl:OK, func:NtAssociateWaitCompletionPacke

t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48


pid:4092, tid:12448, tick:0x35F46F6, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35F4ADE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35F4ADE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35F4ED6, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35F4ED6, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35F52BE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35F52BE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35F56A6, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35F56A6, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35F5A8E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35F5A8E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35F5E85, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35F5E85, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35F626D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35F626D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35F6655, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35F6655, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35F6A4D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35F6A4D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35F6E35, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35F6E35, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35F722C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35F722C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35F7614, lvl:OK, func:NtAssociateWaitCompletionPacke

t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48


pid:4092, tid:12448, tick:0x35F7614, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35F79FC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35F79FC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35F7DF4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35F7DF4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35F81DC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35F81DC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35F85D4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35F85D4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35F89BC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35F89BC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35F8DA4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35F8DA4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35F919B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35F919B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35F9583, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35F9583, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35F997B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35F997B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35F9D63, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35F9D63, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35FA15B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35FA15B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35FA543, lvl:OK, func:NtAssociateWaitCompletionPacke

t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48


pid:4092, tid:12448, tick:0x35FA543, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35FA93A, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35FA93A, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35FAD22, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35FAD22, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35FB11A, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35FB11A, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35FB502, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35FB502, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35FB8EA, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35FB8EA, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35FBCE1, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35FBCE1, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35FC0C9, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35FC0C9, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35FC4C1, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35FC4C1, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35FC8A9, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35FC8A9, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35FCCA1, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35FCCA1, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35FD089, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35FD089, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35FD471, lvl:OK, func:NtAssociateWaitCompletionPacke

t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48


pid:4092, tid:12448, tick:0x35FD471, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35FD868, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35FD868, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35FDC50, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35FDC50, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35FE038, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35FE038, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35FE430, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35FE430, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35FE818, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35FE818, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35FEC00, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35FEC00, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35FEFF8, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35FEFF8, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35FF3EF, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35FF3EF, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35FF7D7, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35FF7D7, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35FFBBF, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35FFBBF, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x35FFFB7, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x35FFFB7, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x36003AE, lvl:OK, func:NtAssociateWaitCompletionPacke

t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48


pid:4092, tid:12448, tick:0x36003AE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3600796, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3600796, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3600B7E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3600B7E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3600F76, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3600F76, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x360135E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x360135E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3601746, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3601746, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3601B3E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3601B3E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3601F26, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3601F26, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x360231D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x360231D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3602715, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3602715, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3602AFD, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3602AFD, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3602EE5, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3602EE5, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x36032DD, lvl:OK, func:NtAssociateWaitCompletionPacke

t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48


pid:4092, tid:12448, tick:0x36032DD, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x36036D4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x36036D4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3603ABC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3603ABC, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3603EA4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3603EA4, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x360428C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x360428C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3604684, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3604684, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3604A6C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3604A6C, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3604E63, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3604E63, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x360525B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x360525B, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3605653, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3605653, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3605A4A, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3605A4A, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3605E32, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3605E32, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x360621A, lvl:OK, func:NtAssociateWaitCompletionPacke

t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48


pid:4092, tid:12448, tick:0x360621A, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3606612, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3606612, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3606A0A, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3606A0A, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3606E01, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3606E01, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x36071E9, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x36071E9, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x36075D1, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x36075D1, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x36079C9, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x36079C9, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3607DB1, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3607DB1, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3608199, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3608199, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3608581, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3608581, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3608978, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3608978, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3608D70, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3608D70, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3609158, lvl:OK, func:NtAssociateWaitCompletionPacke

t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48


pid:4092, tid:12448, tick:0x3609158, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3609550, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3609550, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3609938, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3609938, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3609D20, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3609D20, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x360A117, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x360A117, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x360A4FF, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x360A4FF, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x360A8E7, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x360A8E7, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x360ACCF, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x360ACCF, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x360B0C7, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x360B0C7, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x360B4AF, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x360B4AF, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x360B8A7, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x360B8A7, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x360BC8F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x360BC8F, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x360C086, lvl:OK, func:NtAssociateWaitCompletionPacke

t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48


pid:4092, tid:12448, tick:0x360C086, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x360C46E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x360C46E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x360C856, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x360C856, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x360CC3E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x360CC3E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x360D026, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x360D026, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x360D40E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x360D40E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x360D7F6, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x360D7F6, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x360DBDE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x360DBDE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x360DFC6, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x360DFC6, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x360E3AE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x360E3AE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x360E796, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x360E796, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x360EB7E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x360EB7E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x360EF66, lvl:OK, func:NtAssociateWaitCompletionPacke

t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48


pid:4092, tid:12448, tick:0x360EF66, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x360F34E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x360F34E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x360F746, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x360F746, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x360FB2E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x360FB2E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x360FF16, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x360FF16, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x36102FE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x36102FE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x36106E6, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x36106E6, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3610ACE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3610ACE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3610EB6, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3610EB6, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x361129E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x361129E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3611686, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3611686, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3611A6E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3611A6E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3611E56, lvl:OK, func:NtAssociateWaitCompletionPacke

t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48


pid:4092, tid:12448, tick:0x3611E56, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x361223E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x361223E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3612626, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3612626, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3612A0E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3612A0E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3612DF6, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3612DF6, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x36131DE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x36131DE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x36135C6, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x36135C6, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x36139AE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x36139AE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3613D96, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3613D96, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x361417E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x361417E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3614566, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3614566, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x361494E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x361494E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3614D36, lvl:OK, func:NtAssociateWaitCompletionPacke

t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48


pid:4092, tid:12448, tick:0x3614D36, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x361511E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x361511E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3615506, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3615506, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x36158EE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x36158EE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3615CD6, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3615CD6, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x36160BE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x36160BE, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x36164A6, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x36164A6, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x361688E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x361688E, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3616C76, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3616C76, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x361706D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x361706D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3617455, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3617455, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x361783D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x361783D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3617C25, lvl:OK, func:NtAssociateWaitCompletionPacke

t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48


pid:4092, tid:12448, tick:0x3617C25, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x361800D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x361800D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x36183F5, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x36183F5, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x36187DD, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x36187DD, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3618BC5, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3618BC5, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3618FAD, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3618FAD, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3619395, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3619395, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x361977D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x361977D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3619B65, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3619B65, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x3619F4D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x3619F4D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x361A335, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x361A335, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x361A71D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x361A71D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x361AB05, lvl:OK, func:NtAssociateWaitCompletionPacke

t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48


pid:4092, tid:12448, tick:0x361AB05, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x361AEED, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x361AEED, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x361B2D5, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x361B2D5, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x361B6BD, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x361B6BD, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x361BAA5, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x361BAA5, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x361BE8D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x361BE8D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x361C275, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x361C275, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x361C65D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x361C65D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x361CA45, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x361CA45, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x361CE2D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x361CE2D, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x361D215, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x361D215, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x361D5FD, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x361D5FD, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:12448, tick:0x361D9E5, lvl:OK, func:NtAssociateWaitCompletionPacke

t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48


pid:4092, tid:12448, tick:0x361D9E5, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x361DCD3, lvl:LOG, func:LdrShutdownThread, log:"Thread
terminating..."
pid:4092, tid:1488, tick:0x361DCD3, lvl:OK, func:NtWaitForMultipleObjects, statu
s:0x1, count:0x2, type:0x1, alertable:0x0, objects:0x5C0;0x5D8
pid:4092, tid:1488, tick:0x361DCD3, lvl:OK, func:NtClose, status:0x0, handle:0x5
0C
pid:4092, tid:1488, tick:0x361DCD3, lvl:OK, func:NtClose, status:0x0, handle:0x4
E0
pid:4092, tid:1488, tick:0x361DCD3, lvl:OK, func:NtClose, status:0x0, handle:0x4
6C
pid:4092, tid:1488, tick:0x361DCD3, lvl:OK, func:NtClose, status:0x0, handle:0x4
90
pid:4092, tid:1488, tick:0x361DCD3, lvl:LOG, func:LdrShutdownThread, log:"Thread
terminated successfully!"
pid:4092, tid:12448, tick:0x361DDCD, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:12448, tick:0x361DDCD, lvl:OK, func:NtAssociateWaitCompletionPacke
t, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Se
ssions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x361DDCD, lvl:LOG, func:BaseThreadInitThunk, log:"New
thread started (via BaseThreadInitThunk) at address: 0x77C3C6D0, parameter: 0x76
52D8"
pid:4092, tid:1184, tick:0x361E1B5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x361E1B5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x361E59D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x361E59D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x361E985, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x361E985, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x361ED6D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x361ED6D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x361F155, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x361F155, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x361F53D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x361F53D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x361F925, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x361F925, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses

sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x361FD0D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x361FD0D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36200F5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36200F5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36204DD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36204DD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36208D5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36208D5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3620CBD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3620CBD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36210A5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36210A5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x362148D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x362148D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3621875, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3621875, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3621C5D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3621C5D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3622045, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3622045, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x362242D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x362242D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3622815, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3622815, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses

sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3622BFD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3622BFD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3622FE5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3622FE5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36233CD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36233CD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36237B5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36237B5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3623B9D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3623B9D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3623F85, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3623F85, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x362436D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x362436D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3624755, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3624755, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3624B3D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3624B3D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3624F25, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3624F25, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x362530D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x362530D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36256F5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36256F5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses

sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3625ADD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3625ADD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3625EC5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3625EC5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36262AD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36262AD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3626695, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3626695, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3626A7D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3626A7D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3626E65, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3626E65, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x362724D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x362724D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3627645, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3627645, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3627A2D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3627A2D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3627E15, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3627E15, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36281FD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36281FD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36285E5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36285E5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses

sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36289CD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36289CD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3628DB5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3628DB5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x362919D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x362919D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3629585, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3629585, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x362996D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x362996D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3629D55, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3629D55, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x362A13D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x362A13D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x362A525, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x362A525, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x362A90D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x362A90D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x362ACF5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x362ACF5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x362B0DD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x362B0DD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x362B4C5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x362B4C5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses

sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x362B8AD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x362B8AD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x362BC95, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x362BC95, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x362C07D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x362C07D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x362C465, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x362C465, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x362C84D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x362C84D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x362CC35, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x362CC35, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x362D01D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x362D01D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x362D405, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x362D405, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x362D7ED, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x362D7ED, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x362DBD5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x362DBD5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x362DFBD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x362DFBD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x362E3A5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x362E3A5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses

sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x362E78D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x362E78D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x362EB75, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x362EB75, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x362EF5D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x362EF5D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x362F345, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x362F345, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x362F73C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x362F73C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x362FB24, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x362FB24, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x362FF0C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x362FF0C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36302F4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36302F4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36306DC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36306DC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3630AC4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3630AC4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3630EAC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3630EAC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3631294, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3631294, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses

sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x363167C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x363167C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3631A64, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3631A64, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3631E4C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3631E4C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3632234, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3632234, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x363261C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x363261C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3632A04, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3632A04, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3632DEC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3632DEC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36331D4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36331D4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36335BC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36335BC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36339A4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36339A4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3633D8C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3633D8C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3634174, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3634174, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses

sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x363455C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x363455C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3634944, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3634944, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3634D2C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3634D2C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3635114, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3635114, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36354FC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36354FC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36358F4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36358F4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3635CDC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3635CDC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36360C4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36360C4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36364AC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36364AC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3636894, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3636894, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3636C8C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3636C8C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3637074, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3637074, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses

sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x363745C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x363745C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3637844, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3637844, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3637C2C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3637C2C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3638014, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3638014, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36383FC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36383FC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36387F3, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36387F3, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3638BEB, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3638BEB, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3638FD3, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3638FD3, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36393BB, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36393BB, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36397B2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36397B2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3639B9A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3639B9A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3639F92, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3639F92, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses

sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x363A37A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x363A37A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x363A762, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x363A762, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x363AB4A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x363AB4A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x363AF42, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x363AF42, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x363B32A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x363B32A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x363B712, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x363B712, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x363BAFA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x363BAFA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x363BEE2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x363BEE2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x363C2D9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x363C2D9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x363C6D1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x363C6D1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x363CAB9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x363CAB9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x363CEA1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x363CEA1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses

sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x363D289, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x363D289, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x363D671, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x363D671, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x363DA59, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x363DA59, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x363DE51, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x363DE51, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x363E239, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x363E239, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x363E621, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x363E621, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x363EA09, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x363EA09, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x363EE00, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x363EE00, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x363F1E8, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x363F1E8, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x363F5D0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x363F5D0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x363F9B8, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x363F9B8, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x363FDB0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x363FDB0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses

sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3640198, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3640198, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3640580, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3640580, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3640977, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3640977, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3640D5F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3640D5F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3641147, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3641147, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x364152F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x364152F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3641927, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3641927, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3641D0F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3641D0F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36420F7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36420F7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36424EF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36424EF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36428D7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36428D7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3642CBF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3642CBF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses

sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36430A7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36430A7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x364348F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x364348F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3643877, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3643877, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3643C6E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3643C6E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3644056, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3644056, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x364443E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x364443E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3644826, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3644826, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3644C0E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3644C0E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3644FF6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3644FF6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36453EE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36453EE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36457D6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36457D6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3645BBE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3645BBE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses

sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3645FA6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3645FA6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x364638E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x364638E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3646776, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3646776, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3646B5E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3646B5E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3646F46, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3646F46, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x364732E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x364732E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3647716, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3647716, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3647AFE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3647AFE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3647EF6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3647EF6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36482ED, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36482ED, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36486D5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36486D5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3648ABD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3648ABD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses

sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3648EA5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3648EA5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x364929D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x364929D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3649685, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3649685, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3649A6D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3649A6D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3649E55, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3649E55, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x364A23D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x364A23D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x364A634, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x364A634, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x364AA1C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x364AA1C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x364AE14, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x364AE14, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x364B1FC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x364B1FC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x364B5E4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x364B5E4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x364B9CC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x364B9CC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses

sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x364BDB4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x364BDB4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x364C19C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x364C19C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x364C584, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x364C584, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x364C97C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x364C97C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x364CD73, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x364CD73, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x364D16B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x364D16B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x364D553, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x364D553, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x364D93B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x364D93B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x364DD33, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x364DD33, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x364E11B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x364E11B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x364E503, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x364E503, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x364E8FA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x364E8FA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses

sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x364ECE2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x364ECE2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x364F0CA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x364F0CA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x364F4B2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x364F4B2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x364F8AA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x364F8AA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x364FC92, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x364FC92, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3650089, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3650089, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3650471, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3650471, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3650859, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3650859, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3650C41, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3650C41, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3651039, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3651039, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3651421, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3651421, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3651809, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3651809, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses

sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3651BF1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3651BF1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3651FD9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3651FD9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36523C1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36523C1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36527A9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36527A9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3652BA1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3652BA1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3652F89, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3652F89, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3653371, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3653371, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3653768, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3653768, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3653B60, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3653B60, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3653F48, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3653F48, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3654330, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3654330, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3654718, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3654718, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses

sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3654B00, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3654B00, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3654EE8, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3654EE8, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36552E0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36552E0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36556D7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36556D7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3655ABF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3655ABF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3655EA7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3655EA7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x365629F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x365629F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3656696, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3656696, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3656A7E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3656A7E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3656E66, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3656E66, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x365724E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x365724E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3657636, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3657636, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses

sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3657A1E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3657A1E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3657E06, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3657E06, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36581EE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36581EE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36585D6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36585D6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36589CE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36589CE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3658DB6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3658DB6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x365919E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x365919E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3659586, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3659586, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x365997E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x365997E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3659D66, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3659D66, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x365A14E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x365A14E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x365A536, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x365A536, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses

sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x365A91E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x365A91E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x365AD15, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x365AD15, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x365B0FD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x365B0FD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x365B4E5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x365B4E5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x365B8CD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x365B8CD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x365BCC5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x365BCC5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x365C0AD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x365C0AD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x365C495, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x365C495, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x365C87D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x365C87D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x365CC65, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x365CC65, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x365D04D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x365D04D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x365D435, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x365D435, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses

sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x365D81D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x365D81D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x365DC05, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x365DC05, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x365DFFD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x365DFFD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x365E3E5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x365E3E5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x365E7CD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x365E7CD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x365EBC4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x365EBC4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x365EFAC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x365EFAC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x365F394, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x365F394, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x365F77C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x365F77C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x365FB64, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x365FB64, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x365FF4C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x365FF4C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3660334, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3660334, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses

sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x366072C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x366072C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3660B14, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3660B14, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3660EFC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3660EFC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36612E4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36612E4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36616DB, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36616DB, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3661AC3, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3661AC3, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3661EBB, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3661EBB, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36622B3, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36622B3, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x366269B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x366269B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3662A83, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3662A83, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3662E6B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3662E6B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3663262, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3663262, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses

sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x366364A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x366364A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3663A32, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3663A32, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3663E1A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3663E1A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3664202, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3664202, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36645FA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36645FA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36649E2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36649E2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3664DCA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3664DCA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36651B2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36651B2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36655AA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36655AA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3665992, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3665992, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3665D89, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3665D89, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3666171, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3666171, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses

sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3666559, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3666559, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3666951, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3666951, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3666D39, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3666D39, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3667121, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3667121, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3667518, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3667518, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3667910, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3667910, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3667CF8, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3667CF8, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36680E0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36680E0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36684D8, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36684D8, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36688C0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36688C0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3668CB7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3668CB7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36690AF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36690AF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses

sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3669497, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3669497, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x366987F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x366987F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3669C67, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3669C67, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x366A05F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x366A05F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x366A447, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x366A447, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x366A82F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x366A82F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x366AC17, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x366AC17, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x366AFFF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x366AFFF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x366B3E7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x366B3E7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x366B7CF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x366B7CF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x366BBB7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x366BBB7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x366BFAE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x366BFAE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses

sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x366C396, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x366C396, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x366C77E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x366C77E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x366CB66, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x366CB66, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x366CF5E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x366CF5E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x366D355, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x366D355, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x366D73D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x366D73D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x366DB35, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x366DB35, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x366DF1D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x366DF1D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x366E305, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x366E305, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x366E6ED, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x366E6ED, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x366EAE5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x366EAE5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x366EEDC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x366EEDC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses

sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x366F2D4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x366F2D4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x366F6BC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x366F6BC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x366FAA4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x366FAA4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x366FE8C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x366FE8C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3670274, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3670274, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x367066C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x367066C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3670A54, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3670A54, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3670E3C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3670E3C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3671233, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3671233, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x367161B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x367161B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3671A03, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3671A03, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3671DFB, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3671DFB, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses

sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36721E3, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36721E3, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36725CB, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36725CB, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36729B3, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36729B3, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3672DAA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3672DAA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3673192, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3673192, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x367357A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x367357A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3673962, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3673962, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3673D4A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3673D4A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3674132, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3674132, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x367451A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x367451A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3674912, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3674912, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3674CFA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3674CFA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses

sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36750E2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36750E2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36754CA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36754CA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36758B2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36758B2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3675C9A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3675C9A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3676082, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3676082, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x367646A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x367646A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3676852, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3676852, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3676C4A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3676C4A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3677041, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3677041, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3677429, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3677429, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3677811, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3677811, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3677BF9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3677BF9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses

sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3677FF1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3677FF1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36783D9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36783D9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36787D1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36787D1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3678BB9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3678BB9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3678FA1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3678FA1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3679389, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3679389, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3679780, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3679780, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3679B68, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3679B68, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3679F50, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3679F50, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x367A338, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x367A338, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"

Anda mungkin juga menyukai