_Classes\DirectShow to \REGISTRY\USER\S-1-5-21-2360094602-2602383397-24639908871001\SOFTWARE\CLASSES\Wow6432Node\DirectShow"
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001
\SOFTWARE\CLASSES\DirectShow to \REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\SOFTWARE\CLASSES\Wow6432Node\DirectShow"
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001
\SOFTWARE\Wow6432Node\CLASSES\DirectShow to \REGISTRY\USER\S-1-5-21-2360094602-2
602383397-2463990887-1001\SOFTWARE\CLASSES\Wow6432Node\DirectShow"
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001
_Classes\Interface to \REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1
001\SOFTWARE\CLASSES\Wow6432Node\Interface"
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001
\SOFTWARE\CLASSES\Interface to \REGISTRY\USER\S-1-5-21-2360094602-2602383397-246
3990887-1001\SOFTWARE\CLASSES\Wow6432Node\Interface"
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001
\SOFTWARE\Wow6432Node\CLASSES\Interface to \REGISTRY\USER\S-1-5-21-2360094602-26
02383397-2463990887-1001\SOFTWARE\CLASSES\Wow6432Node\Interface"
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001
_Classes\Media Type to \REGISTRY\USER\S-1-5-21-2360094602-2602383397-24639908871001\SOFTWARE\CLASSES\Wow6432Node\Media Type"
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001
\SOFTWARE\CLASSES\Media Type to \REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\SOFTWARE\CLASSES\Wow6432Node\Media Type"
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001
\SOFTWARE\Wow6432Node\CLASSES\Media Type to \REGISTRY\USER\S-1-5-21-2360094602-2
602383397-2463990887-1001\SOFTWARE\CLASSES\Wow6432Node\Media Type"
pid:4092, tid:2168, tick:0x33D6F82, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001
_Classes\MediaFoundation to \REGISTRY\USER\S-1-5-21-2360094602-2602383397-246399
0887-1001\SOFTWARE\CLASSES\Wow6432Node\MediaFoundation"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001
\SOFTWARE\CLASSES\MediaFoundation to \REGISTRY\USER\S-1-5-21-2360094602-26023833
97-2463990887-1001\SOFTWARE\CLASSES\Wow6432Node\MediaFoundation"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001
\SOFTWARE\Wow6432Node\CLASSES\MediaFoundation to \REGISTRY\USER\S-1-5-21-2360094
602-2602383397-2463990887-1001\SOFTWARE\CLASSES\Wow6432Node\MediaFoundation"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\RegisteredApplications to \REGISTR
Y\MACHINE\SOFTWARE\RegisteredApplications"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\RegisteredApplications
to \REGISTRY\MACHINE\SOFTWARE\RegisteredApplications"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Policies to \REGISTRY\MACHINE\SOFT
WARE\Policies"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Policies to \REGISTRY\
MACHINE\SOFTWARE\Policies"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersio
rtificates to \REGISTRY\MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Microsoft\Driver Signing to \REGIS
TRY\MACHINE\SOFTWARE\Microsoft\Driver Signing"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Driver Signi
ng to \REGISTRY\MACHINE\SOFTWARE\Microsoft\Driver Signing"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Microsoft\DFS to \REGISTRY\MACHINE
\SOFTWARE\Microsoft\DFS"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\DFS to \REGI
STRY\MACHINE\SOFTWARE\Microsoft\DFS"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Microsoft\CTF\TIP to \REGISTRY\MAC
HINE\SOFTWARE\Microsoft\CTF\TIP"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\CTF\TIP to \
REGISTRY\MACHINE\SOFTWARE\Microsoft\CTF\TIP"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Microsoft\CTF\SystemShared to \REG
ISTRY\MACHINE\SOFTWARE\Microsoft\CTF\SystemShared"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\CTF\SystemSh
ared to \REGISTRY\MACHINE\SOFTWARE\Microsoft\CTF\SystemShared"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Microsoft\Cryptography\Services to
\REGISTRY\MACHINE\SOFTWARE\Microsoft\Cryptography\Services"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography
\Services to \REGISTRY\MACHINE\SOFTWARE\Microsoft\Cryptography\Services"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Microsoft\Cryptography\Calais\Read
ers to \REGISTRY\MACHINE\SOFTWARE\Microsoft\Cryptography\Calais\Readers"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography
\Calais\Readers to \REGISTRY\MACHINE\SOFTWARE\Microsoft\Cryptography\Calais\Read
ers"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Microsoft\Cryptography\Calais\Curr
ent to \REGISTRY\MACHINE\SOFTWARE\Microsoft\Cryptography\Calais\Current"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography
\Calais\Current to \REGISTRY\MACHINE\SOFTWARE\Microsoft\Cryptography\Calais\Curr
ent"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Microsoft\COM3 to \REGISTRY\MACHIN
E\SOFTWARE\Microsoft\COM3"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\COM3 to \REG
ISTRY\MACHINE\SOFTWARE\Microsoft\COM3"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Classes\MediaFoundation to \REGIST
RY\MACHINE\SOFTWARE\Classes\Wow6432Node\MediaFoundation"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Classes\MediaFoundatio
n to \REGISTRY\MACHINE\SOFTWARE\Classes\Wow6432Node\MediaFoundation"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \REGISTRY\MACHINE\SOFTWARE\Classes\Wow6432Node\MediaFoundatio
n to \REGISTRY\MACHINE\SOFTWARE\Classes\Wow6432Node\MediaFoundation"
g type: 0x32"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_LoadItem, log:"Skipping confi
g type: 0x28"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_LoadApplicationSvmSettings, l
og:"Done loading embedded app settings."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_LoadBootstrapSystemLayer, log
:"Loading embedded system layers."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_LoadItem, log:"Skipping confi
g type: 0x2E"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_LoadItem, log:"Skipping confi
g type: 0x32"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_LoadItem, log:"Skipping confi
g type: 0x28"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_LoadLayer, log:"Loading inner
layer: Xenocode"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @APPDATA@ (at \Device\HarddiskVolume2\Users\i92segoa\AppDat
a\Roaming) with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @APPDATACOMMON@ (at \Device\HarddiskVolume2\ProgramData) wi
th flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @APPDATALOCAL@ (at \Device\HarddiskVolume2\Users\i92segoa\A
ppData\Local) with flags: 8C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @APPDATALOCALLOW@ (at \Device\HarddiskVolume2\Users\i92sego
a\AppData\LocalLow) with flags: 8C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @APPDIR@ (at \Device\HarddiskVolume2\Users\i92segoa\Desktop
\Firefox SEO) with flags: 4."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @DESKTOP@ (at \Device\HarddiskVolume2\Users\i92segoa\Deskto
p) with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @DESKTOPCOMMON@ (at \Device\HarddiskVolume2\Users\Public\De
sktop) with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @DOCUMENTS@ (at \Device\HarddiskVolume2\Users\i92segoa\Docu
ments) with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @DOCUMENTSCOMMON@ (at \Device\HarddiskVolume2\Users\Public\
Documents) with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @FAVORITES@ (at \Device\HarddiskVolume2\Users\i92segoa\Favo
rites) with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @FAVORITESCOMMON@ (at \Device\HarddiskVolume2\Users\i92sego
a\Favorites) with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @MUSIC@ (at \Device\HarddiskVolume2\Users\i92segoa\Music) w
ith flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @MUSICCOMMON@ (at \Device\HarddiskVolume2\Users\Public\Musi
c) with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @PICTURES@ (at \Device\HarddiskVolume2\Users\i92segoa\Pictu
res) with flags: C."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding root directory @PICTURESCOMMON@ (at \Device\HarddiskVolume2\Users\Public\P
ictures) with flags: C."
g type: 0x17"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \??\C:\Program Files\Common Files to \Device\HarddiskVolume2\
Program Files (x86)\Common Files"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_AddAliasMapping, log:"Adding
alias mapping from \??\C:\Program Files to \Device\HarddiskVolume2\Program Files
(x86)"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:_LoadApplicationSvmNonSystemLa
yers, log:"Done loading embedded app xlayer."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding directory Downloads with flags: 14."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding directory __Xenocode with flags: 3."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"D
uplicate directory __Xenocode will not be added as it is at lower layer."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"D
uplicate directory __Xenocode will not be added as it is at lower layer."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:FormatSandboxPath, log:"Settin
g sandbox path to: \Device\HarddiskVolume2\Users\i92segoa\Desktop\Firefox SEO\da
ta"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding directory Google with flags: 4."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding directory Mozilla with flags: 6."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding directory Adobe with flags: A."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding directory Macromedia with flags: A."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:FormatSandboxPath, log:"Settin
g registry cache path to: \REGISTRY\USER\S-1-5-21-2360094602-2602383397-24639908
87-1001\Software\Spoon\SandboxCache\A527E666CB0D6807"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding directory XSxS with flags: 2."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"D
uplicate directory XSxS will not be added as it is at lower layer."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding directory Mozilla Firefox with flags: 2."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:EssentialInit, log:"Extracted
configuration. Time consumed so far: 16 ms."
pid:4092, tid:2168, tick:0x33D6F92, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x670000, zerobits:0x0, commitsize:0x0, offset:0x210000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6F92, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5B0000
pid:4092, tid:2168, tick:0x33D6F92, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x570000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6F92, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x670000
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding directory Macromed with flags: 2."
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:NtOpenSection, status:0xC00000
34, handle:0x0, access:0xF, path:"\KnownDlls32\Iphlpapi.dll"
pid:4092, tid:2168, tick:0x33D6F92, lvl:LOG, func:RecurseRegistryConfig, log:"Du
plicate regkey Software will not be added as it is at lower layer."
pid:4092, tid:2168, tick:0x33D6F92, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x580000, zerobits:0x0, commitsize:0x0, offset:0x220000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6F92, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x570000
0, address:0x580000
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x580000, zerobits:0x0, commitsize:0x0, offset:0x270000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x570000
pid:4092, tid:2168, tick:0x33D6FA1, lvl:LOG, func:RecurseRegistryConfig, log:"Du
plicate regkey Microsoft will not be added as it is at lower layer."
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x570000, zerobits:0x0, commitsize:0x0, offset:0x220000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x580000
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x580000, zerobits:0x0, commitsize:0x0, offset:0x270000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x570000
pid:4092, tid:2168, tick:0x33D6FA1, lvl:LOG, func:RecurseRegistryConfig, log:"Du
plicate regkey Windows will not be added as it is at lower layer."
pid:4092, tid:2168, tick:0x33D6FA1, lvl:LOG, func:_WrapExistingHandles, log:" W
rapping File handle: 0x28."
pid:4092, tid:2168, tick:0x33D6FA1, lvl:LOG, func:_WrapExistingHandles, log:" W
rapping Key handle: 0x6C."
pid:4092, tid:2168, tick:0x33D6FA1, lvl:LOG, func:_WrapExistingHandles, log:" W
rapping Key handle: 0x70."
pid:4092, tid:2168, tick:0x33D6FA1, lvl:LOG, func:_WrapExistingHandles, log:" W
rapping Key handle: 0x74."
pid:4092, tid:2168, tick:0x33D6FA1, lvl:LOG, func:_WrapExistingHandles, log:" W
rapping File handle: 0x84."
pid:4092, tid:2168, tick:0x33D6FA1, lvl:LOG, func:_WrapExistingHandles, log:" W
rapping Key handle: 0xA4."
pid:4092, tid:2168, tick:0x33D6FA1, lvl:LOG, func:_WrapExistingHandles, log:" W
rapping Key handle: 0xD8."
pid:4092, tid:2168, tick:0x33D6FA1, lvl:LOG, func:_WrapExistingHandles, log:" W
rapping File handle: 0xDC."
pid:4092, tid:2168, tick:0x33D6FA1, lvl:LOG, func:_WrapExistingHandles, log:" W
rapping File handle: 0xF0."
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x570000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x580000
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x580000, zerobits:0x0, commitsize:0x0, offset:0x220000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x570000
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x570000, zerobits:0x0, commitsize:0x0, offset:0x270000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x580000
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x580000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x570000
pid:4092, tid:2168, tick:0x33D6FA1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x570000, zerobits:0x0, commitsize:0x0, offset:0x210000, viewsize:0x100
D8
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"rpcrt4.dll", module:0x77000000
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77000000, name:"I_RpcInitNdrImports", ordinal:0x0, addres
s:0x77036110, image:0x0, caller:0x74E980E2
pid:4092, tid:2168, tick:0x33D6FB1, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\OLE\Tra
cing"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:LOG, func:NtOpenEvent, status:0xC0000034
, handle:0x0, access:0x100000, path:"\Sessions\1\BaseNamedObjects\HookSwitchHook
EnabledEvent"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x20, path:"C:\WINDOWS\system32\IMM32.DLL"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtOpenFile, status:0x0, handle:
0x208, access:0x100001, iostatus:0x0, information:0x1, share:0x5, options:0x60,
path:"C:\WINDOWS\system32\IMM32.DLL"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtCreateSection, status:0x0, ha
ndle:0x20C, access:0x4, pageattribs:0x2, sectionattribs:0x8000000, file:0x208
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x580000, zerobits:0x0, commitsize:0x0, viewsize:0x2A000, disposition:0
x1, type:0x0, protect:0x2, handle:0x20C, path:"C:\WINDOWS\system32\IMM32.DLL"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x580000
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtClose, status:0x0, handle:0x2
0C
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtClose, status:0x0, handle:0x2
08
pid:4092, tid:2168, tick:0x33D6FB1, lvl:LOG, func:LdrGetDllHandle, status:0xC000
0135, name:"C:\WINDOWS\system32\IMM32.DLL"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtOpenSection, status:0x0, hand
le:0x208, access:0xF, path:"\KnownDlls32\IMM32.DLL"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x77670000, zerobits:0x0, commitsize:0x0, viewsize:0x2B000, disposition
:0x1, type:0x800000, protect:0x4, handle:0x208, path:"\KnownDlls32\IMM32.dll"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtClose, status:0x0, handle:0x2
08
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x20, path:"C:\WINDOWS\system32\IMM32.DLL"
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"C:\WINDOWS\system32\IMM32.DLL", module:0x77670000
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"ImmWINNLSEnableIME", ordinal:0x0, address
:0x77688860, image:0x0, caller:0x750628CF
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"ImmWINNLSGetEnableStatus", ordinal:0x0, a
ddress:0x77688890, image:0x0, caller:0x750628E8
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"ImmSendIMEMessageExW", ordinal:0x0, addre
ss:0x77688840, image:0x0, caller:0x75062901
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"ImmSendIMEMessageExA", ordinal:0x0, addre
ss:0x77688820, image:0x0, caller:0x7506291A
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"ImmIMPGetIMEW", ordinal:0x0, address:0x77
688490, image:0x0, caller:0x75062933
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77670000, name:"ImmIMPGetIMEA", ordinal:0x0, address:0x77
688420, image:0x0, caller:0x7506294C
pid:4092, tid:2168, tick:0x33D6FB1, lvl:OK, func:LdrGetProcedureAddressForCaller
trol\MUI\UILanguages\PendingDelete"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:LOG, func:NtOpenKey, status:0xC0000034,
handle:0x0, access:0x20019, path:"\Registry\Machine\Software\Policies\Microsoft\
MUI\Settings"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x580000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x570000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x570000, zerobits:0x0, commitsize:0x0, offset:0x210000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x580000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x580000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x570000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x220, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:LOG, func:NtOpenKey, status:0xC0000034,
handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-26023833972463990887-1001\Control Panel\Desktop\MuiCached\MachineLanguageConfiguration"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x224, access:0x20019, path:"\Registry\Machine\System\CurrentControlSet\Control\M
UI\Settings\LanguageConfiguration"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:LOG, func:NtEnumerateValueKey, status:0x
8000001A, index:0x0, class:0x1, length:0x200, resultlength:0x2000B09, handle:0x2
24, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\MUI\Settings\LanguageCo
nfiguration"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtClose, status:0x0, handle:0x2
24
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtClose, status:0x0, handle:0x2
20
pid:4092, tid:2168, tick:0x33D6FC1, lvl:LOG, func:NtOpenKey, status:0xC0000034,
handle:0x0, access:0x20019, path:"\Registry\Machine\Software\Policies\Microsoft\
MUI\Settings"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x220, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x570000, zerobits:0x0, commitsize:0x0, offset:0x210000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x580000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x580000, zerobits:0x0, commitsize:0x0, offset:0x220000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x570000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x570000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x580000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:LOG, func:RecurseRegistryConfig, log:"Du
plicate regkey Classes will not be added as it is at lower layer."
pid:4092, tid:2168, tick:0x33D6FC1, lvl:LOG, func:RecurseRegistryConfig, log:"Du
me:"crypt32.dll", module:0x77870000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"shell32.dll", handle:0x75670000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"shell32.dll", module:0x75670000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"shell32.dll", module:0x75670000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"shell32.dll", module:0x75670000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"shell32.dll", module:0x75670000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"shell32.dll", module:0x75670000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:LOG, func:NtOpenSection, status:0xC00000
34, handle:0x0, access:0xF, path:"\KnownDlls32\mpr.dll"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:LOG, func:NtQueryAttributesFile, status:
0xC0000034, path:"C:\Users\i92segoa\Desktop\Firefox SEO\mpr.dll"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x20, path:"C:\WINDOWS\SYSTEM32\mpr.dll"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtOpenFile, status:0x0, handle:
0x2C8, access:0x100021, iostatus:0x0, information:0x1, share:0x5, options:0x60,
path:"C:\WINDOWS\SYSTEM32\mpr.dll"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtCreateSection, status:0x0, ha
ndle:0x2CC, access:0xF, pageattribs:0x10, sectionattribs:0x1000000, file:0x2C8
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x62CE0000, zerobits:0x0, commitsize:0x0, viewsize:0x16000, disposition
:0x1, type:0x800000, protect:0x4, handle:0x2CC, path:"C:\WINDOWS\SYSTEM32\mpr.dl
l"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtClose, status:0x0, handle:0x2
CC
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtClose, status:0x0, handle:0x2
C8
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x2CC, access:0x20019, path:"\REGISTRY\MACHINE\system\CurrentControlSet\control
\NetworkProvider\HwOrder"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtNotifyChangeKey, status:0x103
, event:0x2C8, iostatus:0x103, information:0x0, filter:0x4, watch:0x0, length:0x
0, async:0x1, handle:0x2CC, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control
\NetworkProvider\HwOrder"
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtCreateSemaphore, status:0x0,
handle:0x2D0, access:0x100003, initialcount:0x0, maxcount:0x7FFFFFFF
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:NtCreateSemaphore, status:0x0,
handle:0x2D4, access:0x100003, initialcount:0x0, maxcount:0x7FFFFFFF
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"mpr.dll", handle:0x62CE0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"mpr.dll", module:0x62CE0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"mpr.dll", module:0x62CE0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"advapi32.dll", handle:0x77B40000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"kernelbase.dll", module:0x776F0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"ntdll.dll", module:0x77C10000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"ntdll.dll", module:0x77C10000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"kernel32.dll", module:0x74CD0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"kernelbase.dll", module:0x776F0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"kernelbase.dll", module:0x776F0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"advapi32.dll", module:0x77B40000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"advapi32.dll", module:0x77B40000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"shlwapi.dll", handle:0x77BC0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"shlwapi.dll", module:0x77BC0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"advapi32.dll", handle:0x77B40000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"advapi32.dll", module:0x77B40000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"advapi32.dll", module:0x77B40000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"advapi32.dll", module:0x77B40000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"advapi32.dll", module:0x77B40000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"advapi32.dll", module:0x77B40000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"advapi32.dll", module:0x77B40000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"advapi32.dll", module:0x77B40000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"advapi32.dll", module:0x77B40000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"advapi32.dll", module:0x77B40000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"sechost.dll", handle:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"sechost.dll", handle:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK,
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK,
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK,
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK,
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK,
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK,
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK,
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK,
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK,
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK,
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK,
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK,
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK,
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK,
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK,
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK,
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK,
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK,
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK,
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK,
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK,
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK,
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK,
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK,
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK,
me:"sechost.dll", module:0x776A0000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK,
x0, module:"ole32.dll", handle:0x75580000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK,
me:"ole32.dll", module:0x75580000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK,
me:"ole32.dll", module:0x75580000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK,
me:"ole32.dll", module:0x75580000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK,
func:LdrGetDllHandle, status:0x0, na
func:LdrGetDllHandle, status:0x0, na
func:LdrGetDllHandle, status:0x0, na
func:LdrGetDllHandle, status:0x0, na
func:LdrGetDllHandle, status:0x0, na
func:LdrGetDllHandle, status:0x0, na
func:LdrGetDllHandle, status:0x0, na
func:LdrGetDllHandle, status:0x0, na
func:LdrGetDllHandle, status:0x0, na
func:LdrGetDllHandle, status:0x0, na
func:LdrGetDllHandle, status:0x0, na
func:LdrGetDllHandle, status:0x0, na
func:LdrGetDllHandle, status:0x0, na
func:LdrGetDllHandle, status:0x0, na
func:LdrGetDllHandle, status:0x0, na
func:LdrGetDllHandle, status:0x0, na
func:LdrGetDllHandle, status:0x0, na
func:LdrGetDllHandle, status:0x0, na
func:LdrGetDllHandle, status:0x0, na
func:LdrGetDllHandle, status:0x0, na
func:LdrGetDllHandle, status:0x0, na
func:LdrGetDllHandle, status:0x0, na
func:LdrGetDllHandle, status:0x0, na
func:LdrGetDllHandle, status:0x0, na
func:LdrGetDllHandle, status:0x0, na
func:LdrLoadDll, status:0x0, flags:0
func:LdrGetDllHandle, status:0x0, na
func:LdrGetDllHandle, status:0x0, na
func:LdrGetDllHandle, status:0x0, na
func:LdrGetDllHandle, status:0x0, na
me:"ole32.dll", module:0x75580000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"ole32.dll", module:0x75580000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"ole32.dll", module:0x75580000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"ole32.dll", module:0x75580000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"user32.dll", handle:0x75050000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"user32.dll", module:0x75050000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"user32.dll", module:0x75050000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"user32.dll", module:0x75050000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"user32.dll", module:0x75050000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"user32.dll", module:0x75050000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"user32.dll", module:0x75050000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"user32.dll", module:0x75050000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"user32.dll", module:0x75050000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"user32.dll", module:0x75050000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"user32.dll", module:0x75050000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"user32.dll", module:0x75050000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"user32.dll", module:0x75050000
pid:4092, tid:2168, tick:0x33D6FC1, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"user32.dll", module:0x75050000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:LOG, func:InterceptAPI32, log:"Didn't fi
nd method CreateWindowA."
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"user32.dll", module:0x75050000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:LOG, func:InterceptAPI32, log:"Didn't fi
nd method CreateWindowW."
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"ws2_32.dll", handle:0x775F0000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"ws2_32.dll", module:0x775F0000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"ws2_32.dll", module:0x775F0000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"ws2_32.dll", module:0x775F0000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"ws2_32.dll", module:0x775F0000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"ws2_32.dll", module:0x775F0000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"ws2_32.dll", module:0x775F0000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"ws2_32.dll", module:0x775F0000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"ws2_32.dll", module:0x775F0000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"ws2_32.dll", module:0x775F0000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"ws2_32.dll", module:0x775F0000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"ws2_32.dll", module:0x775F0000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"ws2_32.dll", module:0x775F0000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"ws2_32.dll", module:0x775F0000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"ws2_32.dll", module:0x775F0000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"ws2_32.dll", module:0x775F0000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"ws2_32.dll", module:0x775F0000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"ws2_32.dll", module:0x775F0000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x570000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5A0000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding directory x64 with flags: 3."
pid:4092, tid:2168, tick:0x33D6FD0, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding directory x86 with flags: 3."
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5A0000, zerobits:0x0, commitsize:0x0, offset:0x1E0000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x570000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x570000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5A0000
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x82, path:"C:\Users\i92segoa\Desktop\Firefox SEO\__Xenocode\x86\vmx
.dll"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtOpenFile, status:0x0, handle:
0x2D8, access:0x100021, iostatus:0x0, information:0x0, share:0x5, options:0x60,
path:"C:\Users\i92segoa\Desktop\Firefox SEO\__Xenocode\x86\vmx.dll"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtCreateSection, status:0x0, ha
ndle:0x2E0, access:0xF, pageattribs:0x10, sectionattribs:0x1000000, file:0x2D8
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
E8
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtSetInformationProcess, status
:0x0, class:0x1, length:0x38
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
EC
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x10000000, zerobits:0x0, commitsize:0x0, viewsize:0x175000, dispositio
n:0x1, type:0x800000, protect:0x4, handle:0x2E0, path:"C:\Users\i92segoa\Desktop
\Firefox SEO\__Xenocode\x86\vmx.dll"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:LOG, func:NtOpenSection, status:0xC00000
34, handle:0x0, access:0xF, path:"\KnownDlls32\WININET.dll"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:LOG, func:NtOpenSection, status:0xC00000
34, handle:0x0, access:0xF, path:"\KnownDlls32\Secur32.dll"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
E0
F8
pid:4092, tid:2168, tick:0x33D6FD0, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x2F8, iostatus:0x0, information:0x19E8DC, code:0x12000F, inle
n:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
F8
pid:4092, tid:2168, tick:0x33D6FD0, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x2F8, iostatus:0x0, information:0x19E8DC, code:0x12000F, inle
n:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
F8
pid:4092, tid:2168, tick:0x33D6FD0, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x2F8, iostatus:0x0, information:0x19E8DC, code:0x12000F, inle
n:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
F8
pid:4092, tid:2168, tick:0x33D6FD0, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x2F8, iostatus:0x0, information:0x19E8DC, code:0x12000F, inle
n:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
F8
pid:4092, tid:2168, tick:0x33D6FD0, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x2F8, iostatus:0x0, information:0x19E8DC, code:0x12000F, inle
n:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
F8
pid:4092, tid:2168, tick:0x33D6FD0, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x2F8, iostatus:0x0, information:0x19E8DC, code:0x12000F, inle
n:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
F8
pid:4092, tid:2168, tick:0x33D6FD0, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x2F8, iostatus:0x0, information:0x19E8DC, code:0x12000F, inle
n:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
F8
pid:4092, tid:2168, tick:0x33D6FD0, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x2F8, iostatus:0x0, information:0x19E8DC, code:0x12000F, inle
n:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
F8
pid:4092, tid:2168, tick:0x33D6FD0, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x2F8, iostatus:0x0, information:0x19E8DC, code:0x12000F, inle
n:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
F8
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x2F8, iostatus:0x0, information:0x68, code:0x12000F, inlen:0x38, outl
en:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtClose, status:0x0, handle:0x2
F8
pid:4092, tid:2168, tick:0x33D6FD0, lvl:LOG, func:NtOpenSection, status:0xC00000
34, handle:0x0, access:0xF, path:"\KnownDlls32\dhcpcsvc.DLL"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:LOG, func:NtQueryAttributesFile, status:
0xC0000034, path:"C:\Users\i92segoa\Desktop\Firefox SEO\dhcpcsvc.DLL"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x20, path:"C:\WINDOWS\SYSTEM32\dhcpcsvc.DLL"
pid:4092, tid:2168, tick:0x33D6FD0, lvl:OK, func:NtOpenFile, status:0x0, handle:
0x2C0, access:0x100021, iostatus:0x0, information:0x1, share:0x5, options:0x60,
path:"C:\WINDOWS\SYSTEM32\dhcpcsvc.DLL"
.dll"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
2C
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
28
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtCreateSemaphore, status:0x0,
handle:0x334, access:0x100003, initialcount:0x0, maxcount:0x7FFFFFFF
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtCreateSemaphore, status:0x0,
handle:0x338, access:0x100003, initialcount:0x0, maxcount:0x7FFFFFFF
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtOpenFile, status:0x0, handle:
0x340, access:0x100003, iostatus:0x0, information:0x0, share:0x7, options:0x20,
path:"\Device\KsecDD"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, iostatus:0x0, information:0x0, code:0x390402, inlen:0x68, outlen:0x8, handle
:0x340, path:"\Device\KsecDD"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"C:\WINDOWS\system32\rsaenh.dll", handle:0x705E0000
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPAcquireContext", ordinal:0x0, address:0
x705E4CA0, image:0x0, caller:0x706542D4
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPReleaseContext", ordinal:0x0, address:0
x705E8930, image:0x0, caller:0x706542D4
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPGenKey", ordinal:0x0, address:0x705E600
0, image:0x0, caller:0x706542D4
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPDeriveKey", ordinal:0x0, address:0x705F
ADE0, image:0x0, caller:0x706542D4
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPDestroyKey", ordinal:0x0, address:0x705
E6D30, image:0x0, caller:0x706542D4
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPSetKeyParam", ordinal:0x0, address:0x70
5FC7D0, image:0x0, caller:0x706542D4
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPGetKeyParam", ordinal:0x0, address:0x70
5E8800, image:0x0, caller:0x706542D4
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPExportKey", ordinal:0x0, address:0x705E
5B80, image:0x0, caller:0x706542D4
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPImportKey", ordinal:0x0, address:0x705E
7440, image:0x0, caller:0x706542D4
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPEncrypt", ordinal:0x0, address:0x705F98
E0, image:0x0, caller:0x706542D4
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPDecrypt", ordinal:0x0, address:0x705E95
A0, image:0x0, caller:0x706542D4
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPCreateHash", ordinal:0x0, address:0x705
E8040, image:0x0, caller:0x706542D4
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPHashData", ordinal:0x0, address:0x705E6
A30, image:0x0, caller:0x706542D4
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x705E0000, name:"CPHashSessionKey", ordinal:0x0, address:0
x705FA650, image:0x0, caller:0x706542D4
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrGetProcedureAddressForCaller
"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Cryptography"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"MachineGuid", class:0x2, length:0x90, resultlength:0x56, handle:0x34C, path:
"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Cryptography"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"MachineGuid", class:0x2, length:0x90, resultlength:0x56, handle:0x34C, path:
"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Cryptography"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
4C
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptog
raphy\Offload"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x34C, c
lass:0x1, length:0x400, returnlength:0x24, sid:"S-1-5-21-2360094602-2602383397-2
463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
4C
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x705E0000
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptog
raphy\DESHashSessionKeyBackward"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
20
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, iostatus:0x0, information:0xE0, code:0x390402, inlen:0x40, outlen:0x180, han
dle:0x340, path:"\Device\KsecDD"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"C:\WINDOWS\system32\bcryptprimitives.dll", handle:0x74AB0000
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74AB0000, name:"GetHashInterface", ordinal:0x0, address:0
x74AC98C0, image:0x0, caller:0x72B3146B
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
20
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtDeviceIoControlFile, status:0
x105, event:0x320, iostatus:0x105, information:0x70, code:0x12001B, inlen:0x3C,
outlen:0x3C, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
20
pid:4092, tid:9004, tick:0x33D6FE0, lvl:LOG, func:BaseThreadInitThunk, log:"New
thread started (via BaseThreadInitThunk) at address: 0x10039100, parameter: 0x10
14D36C"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x320, iostatus:0x0, information:0x70, code:0x12001B, inlen:0x3C, outl
en:0x3C, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
20
pid:4092, tid:9004, tick:0x33D6FE0, lvl:LOG, func:NtOpenSection, status:0xC00000
34, handle:0x0, access:0xF, path:"\KnownDlls32\iertutil.dll"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x320, iostatus:0x0, information:0x50, code:0x120007, inlen:0x30, outl
en:0x4, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
20
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtDeviceIoControlFile, status:
0xC0000225, event:0x320, iostatus:0x0, information:0x19E8D4, code:0x12000F, inle
n:0x38, outlen:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
20
88
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5B0000, zerobits:0x0, commitsize:0x0, offset:0x210000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5A0000
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5A0000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x10, path:"C:\Users\i92segoa\Desktop\Firefox SEO\"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5B0000
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x75670000
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x388, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24639908
87-1001\Software\Microsoft\Windows\CurrentVersion\Explorer"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5B0000, zerobits:0x0, commitsize:0x0, offset:0x210000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5A0000
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5A0000, zerobits:0x0, commitsize:0x0, offset:0x220000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5B0000
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:NtQueryAttributesFile, status:
0xC0000034, path:"C:\WINDOWS\system32\rpcss.dll"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:LOG, func:LdrGetDllHandle, status:0xC000
0135, name:"C:\WINDOWS\system32\rpcss.dll"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5B0000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5A0000
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x74DC0000
pid:4092, tid:9004, tick:0x33D6FE0, lvl:LOG, func:RecurseRegistryConfig, log:"Du
plicate regkey UserAssist will not be added as it is at lower layer."
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x380, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24639908
87-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1"
pid:4092, tid:9004, tick:0x33D6FE0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\K
nownFolders"
pid:4092, tid:2168, tick:0x33D6FE0, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x74DC0000
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtClose, status:0x0, handle:0x3
80
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5A0000, zerobits:0x0, commitsize:0x0, offset:0x220000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5B0000
pid:4092, tid:9004, tick:0x33D6FE0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5B0000, zerobits:0x0, commitsize:0x0, offset:0x270000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
xplorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"
pid:4092, tid:9004, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Stream", class:0x2, length:0x90, resultlength:0x10, handle:0x3AC, pa
th:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Expl
orer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}"
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"PublishExpandedPath", class:0x2, length:0x90, resultlength:0x10, handle:0x3A
C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion
\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x384, access:0x1, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVe
rsion\Policies\Explorer"
pid:4092, tid:9004, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DefinitionFlags", class:0x2, length:0x90, resultlength:0x10, handle:
0x3AC, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVer
sion\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"NoPropertiesRecycleBin", class:0x2, length:0x90, resultlength:0x19EF
F0, handle:0x384, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Windows\CurrentVers
ion\Policies\Explorer"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x3
84
pid:4092, tid:9004, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Attributes", class:0x2, length:0x90, resultlength:0x10, handle:0x3AC
, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\
Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"
pid:4092, tid:9004, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"FolderTypeID", class:0x2, length:0x90, resultlength:0x10, handle:0x3
AC, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersio
n\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}"
pid:4092, tid:9004, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"InitFolderHandler", class:0x2, length:0x90, resultlength:0x10, handl
e:0x3AC, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentV
ersion\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x384, access:0x1, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVe
rsion\Policies\Explorer"
pid:4092, tid:9004, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Micro
soft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55
-7B8E7F157091}\PropertyBag"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"NoControlPanel", class:0x2, length:0x90, resultlength:0x0, handle:0x
384, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Windows\CurrentVersion\Policies\
Explorer"
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x3
AC
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x3
84
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x384, access:0x1, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVe
rsion\Policies\Explorer"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"NoSetFolders", class:0x2, length:0x90, resultlength:0x0, handle:0x38
4, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Windows\CurrentVersion\Policies\Ex
plorer"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x3
84
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x3AC, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24639908
87-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1"
pid:4092, tid:9004, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\K
nownFolders"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x3
AC
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x384, access:0x1, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVe
rsion\Policies\Explorer"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"NoInternetIcon", class:0x2, length:0x90, resultlength:0x19EFF0, hand
le:0x384, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Windows\CurrentVersion\Poli
cies\Explorer"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x3
84
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x3B4, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246399
0887-1001"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x9, path:"\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\Cur
rentVersion\ShellCompatibility\Applications\firefox.exe"
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x3B8, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folder
s"
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x3
B4
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Local AppData", class:0x2, length:0x90, resultlength:0x44, handle:0x3B8, pat
h:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Micros
oft\Windows\CurrentVersion\Explorer\User Shell Folders"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x384, access:0x1, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVe
rsion\Explorer\Desktop\NameSpace"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"ValidateRegItems", class:0x2, length:0x90, resultlength:0x19F114, ha
ndle:0x384, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Curre
ntVersion\Explorer\Desktop\NameSpace"
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x3
A4
s:0x0, module:0x76B00000
pid:4092, tid:9004, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"ParsingName", class:0x2, length:0x90, resultlength:0x10, handle:0x3A
C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion
\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}"
pid:4092, tid:9004, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"InfoTip", class:0x2, length:0x90, resultlength:0x10, handle:0x3AC, p
ath:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Exp
lorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x76B00000
pid:4092, tid:9004, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"LocalizedName", class:0x2, length:0x90, resultlength:0x10, handle:0x
3AC, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersi
on\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x76B00000
pid:4092, tid:9004, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Icon", class:0x2, length:0x90, resultlength:0x10, handle:0x3AC, path
:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explor
er\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x76B00000
pid:4092, tid:9004, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Security", class:0x2, length:0x90, resultlength:0x10, handle:0x3AC,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Ex
plorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:9004, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"StreamResource", class:0x2, length:0x90, resultlength:0x10, handle:0
x3AC, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVers
ion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}"
pid:4092, tid:9004, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"StreamResourceType", class:0x2, length:0x90, resultlength:0x10, hand
le:0x3AC, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Current
Version\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}"
pid:4092, tid:9004, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"LocalRedirectOnly", class:0x2, length:0x90, resultlength:0x10, handl
e:0x3AC, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentV
ersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}"
pid:4092, tid:9004, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Roamable", class:0x2, length:0x90, resultlength:0x10, handle:0x3AC,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Ex
plorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5A0000, zerobits:0x0, commitsize:0x0, offset:0x210000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5B0000
pid:4092, tid:9004, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"PreCreate", class:0x2, length:0x90, resultlength:0x10, handle:0x3AC,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\E
xplorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5B0000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:9004, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
\S-1-5-21-2360094602-2602383397-2463990887-1001"
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x3
A4
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x3
AC
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x3
B8
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x76B00000
pid:4092, tid:9004, tick:0x33D6FF0, lvl:LOG, func:NtCreateFile, status:0xC000003
5, handle:0x0, access:0x100001, iostatus:0xDD, information:0xBD20DC, attribs:0x8
0, share:0x3, disposition:0x2, options:0x204021, path:"C:\Users\i92segoa"
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x10, path:"C:\Users\i92segoa"
pid:4092, tid:9004, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\Cur
rentVersion\Explorer\KnownFolderSettings"
pid:4092, tid:9004, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\Cur
rentVersion\Explorer\KnownFolderSettings"
pid:4092, tid:9004, tick:0x33D6FF0, lvl:LOG, func:NtCreateFile, status:0xC000003
5, handle:0x0, access:0x100001, iostatus:0x0, information:0xFFFFFFFF, attribs:0x
80, share:0x3, disposition:0x2, options:0x204021, path:"C:\Users\i92segoa\AppDat
a\Local"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x92, handle:0x386, path:"\REGISTRY\USER\S-1-5-21
-2360094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x386, path:"\REGISTRY\USER\S-1-5-21-23
60094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder"
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x10, path:"C:\Users\i92segoa\AppData\Local"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5A0000, zerobits:0x0, commitsize:0x0, offset:0x210000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5B0000
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5B0000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5A0000
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5A0000, zerobits:0x0, commitsize:0x0, offset:0x220000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5B0000
pid:4092, tid:9004, tick:0x33D6FF0, lvl:LOG, func:NtCreateFile, status:0xC000003
5, handle:0x0, access:0x100001, iostatus:0x0, information:0xFFFFFFFF, attribs:0x
80, share:0x3, disposition:0x2, options:0x204021, path:"C:\Users\i92segoa\AppDat
a\Local\Microsoft\Windows\INetCache"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:RecurseRegistryConfig, log:"Du
plicate regkey Wow6432Node will not be added as it is at lower layer."
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5B0000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5A0000
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x2016, path:"C:\Users\i92segoa\AppData\Local\Microsoft\Windows\INet
Cache"
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x72AAA000, class:0x0, length:0x1C, resultlength:0x1C
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5A0000, zerobits:0x0, commitsize:0x0, offset:0x270000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"OLEAUT32.dll", handle:0x754E0000
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5B0000
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x754E0000, ordinal:0x2, address:0x754FAB60, image:0x0, cal
ler:0x72A4ABED
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x754E0000, ordinal:0x7, address:0x754F2860, image:0x0, cal
ler:0x72A4ABED
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:NtSetInformationProcess, status
:0x0, class:0xC, length:0x4
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x2016, path:"C:\Users\i92segoa\AppData\Local\Microsoft\Windows\INet
Cache"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:RecurseRegistryConfig, log:"Du
plicate regkey Wow6432Node will not be added as it is at lower layer."
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:NtSetInformationProcess, status
:0x0, class:0xC, length:0x4
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x754E0000, ordinal:0x6, address:0x754FAC10, image:0x0, cal
ler:0x72A4ABED
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5B0000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5A0000
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x3B8, c
lass:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-2602383397-24
63990887-1001", attributes:0x0
pid:4092, tid:9004, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x3
B8
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5A0000, zerobits:0x0, commitsize:0x0, offset:0x220000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5B0000
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:RecurseRegistryConfig, log:"Du
plicate regkey CLSID will not be added as it is at lower layer."
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5B0000, zerobits:0x0, commitsize:0x0, offset:0x270000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5A0000
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:RecurseRegistryConfig, log:"Du
plicate regkey CLSID will not be added as it is at lower layer."
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:RecurseRegistryConfig, log:"Du
plicate regkey Interface will not be added as it is at lower layer."
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5A0000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x100
Software\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"CacheMode", class:0x2, length:0x90, resultlength:0x29CF4AC, handle:0
x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\Softwa
re\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtOpenEvent, status:0x0, handle
:0x3E0, access:0x100001, path:"\KernelObjects\MaximumCommitCondition"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x3E4, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies\Microsoft\Wind
ows\CurrentVersion\Internet Settings"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x74DC0000
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"EnableHttp1_1", class:0x2, length:0x90, resultlength:0x10, handle:0x
3E4, path:"\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\
Internet Settings"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x76A70000
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"EnableHttp1_1", class:0x2, length:0x90, resultlength:0x10, handle:0x
3A8, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWAR
E\Policies\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"EnableHttp1_1", class:0x2, length:0x90, resultlength:0x10, handle:0x370, pat
h:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\Software\Micros
oft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"ProxyHttp1.1", class:0x2, length:0x90, resultlength:0x10, handle:0x3
E4, path:"\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\I
nternet Settings"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\Microsoft\Ole\App
Compat\DisableClsidFreeActivatableClasses"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"ProxyHttp1.1", class:0x2, length:0x90, resultlength:0x10, handle:0x3
A8, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE
\Policies\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ProxyHttp1.1", class:0x2, length:0x90, resultlength:0x10, handle:0x370, path
:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\Software\Microso
ft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"EnableNegotiate", class:0x2, length:0x90, resultlength:0x10, handle:0x370, p
ath:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\Software\Micr
osoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DisableBasicOverClearChannel", class:0x2, length:0x90, resultlength:
0x10, handle:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24639908
87-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtOpenSection, status:0x0, hand
le:0x3E8, access:0x4, path:"\Sessions\1\BaseNamedObjects\Global\__ComCatalogCach
e__"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"EnableAutoProxyResultCache", class:0x2, length:0x90, resultlength:0x
10, handle:0x3A8, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887
-1001\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x6D0000, zerobits:0x0, commitsize:0x0, offset:0x0, viewsize:0x1000, di
sposition:0x1, type:0x0, protect:0x2, handle:0x3E8, path:"\BaseNamedObjects\__Co
mCatalogCache__"
ion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DisableNTLMPreAuth", class:0x2, length:0x90, resultlength:0x7834A0,
handle:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-100
1\Software\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"CertCacheNoValidate", class:0x2, length:0x90, resultlength:0x7834A0,
handle:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-10
01\Software\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_D
ISABLE_NOTIFY_UNVERIFIED_SPN_KB2385266"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft
\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_NOTIFY_UNVERIFIED_SPN_KB2
385266"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_C
OMPAT_USE_CONNECTION_BASED_NEGOTIATE_AUTH_KB2151543"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft
\Internet Explorer\Main\FeatureControl\FEATURE_COMPAT_USE_CONNECTION_BASED_NEGOT
IATE_AUTH_KB2151543"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"HttpDefaultExpiryTimeSecs", class:0x2, length:0x90, resultlength:0x2
9CFC0C, handle:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246399
0887-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"FtpDefaultExpiryTimeSecs", class:0x2, length:0x90, resultlength:0x29
CFC0C, handle:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990
887-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x3FC, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24639908
87-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"DisableCachingOfSSLPages", class:0x2, length:0x90, resultlength:0x10, handle
:0x3FC, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFT
WARE\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x3
FC
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"LeashLegacyCookies", class:0x2, length:0x90, resultlength:0x80, hand
le:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\So
ftware\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DialupUseLanSettings", class:0x2, length:0x90, resultlength:0x80, ha
ndle:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\
Software\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DialupUseLanSettings", class:0x2, length:0x90, resultlength:0x80, ha
ndle:0x3F4, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Curre
ntVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"SendExtraCRLF", class:0x2, length:0x90, resultlength:0x80, handle:0x
370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\Softwar
e\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"BypassHTTPNoCacheCheck", class:0x2, length:0x90, resultlength:0x80,
handle:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-100
1\Software\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"BypassHTTPNoCacheCheck", class:0x2, length:0x90, resultlength:0x80,
handle:0x3F4, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Cur
rentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"BypassSSLNoCacheCheck", class:0x2, length:0x90, resultlength:0x80, h
andle:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001
\Software\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"BypassSSLNoCacheCheck", class:0x2, length:0x90, resultlength:0x80, h
andle:0x3F4, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Curr
entVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"EnableHttpTrace", class:0x2, length:0x90, resultlength:0x80, handle:
0x3F4, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVer
sion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"NoCheckAutodialOverRide", class:0x2, length:0x90, resultlength:0x80,
handle:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-10
01\Software\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"NoCheckAutodialOverRide", class:0x2, length:0x90, resultlength:0x80,
handle:0x3F4, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Cu
rrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_S
CH_SEND_AUX_RECORD_KB_2618444"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft
\Internet Explorer\Main\FeatureControl\FEATURE_SCH_SEND_AUX_RECORD_KB_2618444"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DontUseDNSLoadBalancing", class:0x2, length:0x90, resultlength:0xEE,
handle:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-10
01\Software\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DontUseDNSLoadBalancing", class:0x2, length:0x90, resultlength:0xEE,
handle:0x3F4, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Cu
rrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"ShareCredsWithWinHttp", class:0x2, length:0x90, resultlength:0xEE, h
andle:0x3F4, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Curr
entVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"MimeExclusionListForCache", class:0x2, length:0x90, resultlength:0x6
80000, handle:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990
887-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"MimeExclusionListForCache", class:0x2, length:0x90, resultlength:0xF
FFFFFB6, handle:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24639
90887-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"HeaderExclusionListForCache", class:0x2, length:0x90, resultlength:0
x728EE23B, handle:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246
3990887-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_E
NABLE_TOKEN_BINDING"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft
\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_TOKEN_BINDING"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DnsCacheEnabled", class:0x2, length:0x90, resultlength:0x41004D, han
dle:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\S
oftware\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DnsCacheEntries", class:0x2, length:0x90, resultlength:0x29CF4E8, ha
ndle:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\
Software\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DnsCacheTimeout", class:0x2, length:0x90, resultlength:0x29CF4E8, ha
ndle:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\
Software\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"WarnOnPost", class:0x2, length:0x90, resultlength:0x29CF49C, handle:
0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\Softw
are\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"WarnAlwaysOnPost", class:0x2, length:0x90, resultlength:0x29CF49C, h
andle:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001
\Software\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x92, handle:0x3C2, path:"\Registry\User\S-1-5-21
-2360094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"WarnOnZoneCrossing", class:0x2, length:0x90, resultlength:0x10, handle:0x370
, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\Software\M
icrosoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x3C2, path:"\Registry\User\S-1-5-21-23
60094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"WarnOnBadCertRecving", class:0x2, length:0x90, resultlength:0x10, ha
ndle:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\
Software\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"WarnOnPostRedirect", class:0x2, length:0x90, resultlength:0x10, hand
le:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\So
ftware\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\Registry\User\S-1-5-21-2360094602-260238339
7-2463990887-1001_Classes\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"AlwaysDrainOnRedirect", class:0x2, length:0x90, resultlength:0x10, h
andle:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001
\Software\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"WarnOnHTTPSToHTTPRedirect", class:0x2, length:0x90, resultlength:0x1
0, handle:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24639908871001\Software\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x3F8, access:0x20019, path:"\Registry\Machine\Software\Classes\CLSID\{1F486A52
-3CB1-48FD-8F50-B8DC300D9F9D}"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"TcpAutotuning", class:0x2, length:0x90, resultlength:0x29CF500, hand
le:0x3F4, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Current
Version\Internet Settings"
A4
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\WOW6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9
F9D}"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"NameSpace_Callout", class:0x2, length:0x90, resultlength:0x52, handle:0x38C,
path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"NameSpace_Callout", class:0x2, length:0x90, resultlength:0x52, handle:0x38C,
path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"", class:0x2, length:0x90, resultlength:0x3C, handle:0x3FA, path:"\REGISTRY\
MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D
}"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x3C4, access:0x2000000, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\
WinSock2\Parameters\Protocol_Catalog9"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0xBA, handle:0x3FA, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Serial_Access_Num", class:0x2, length:0x90, resultlength:0x10, handle:0x3C4,
path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Proto
col_Catalog9"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x3FA, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtNotifyChangeKey, status:0x103
, event:0x3A4, iostatus:0x103, information:0x0, filter:0x1, watch:0x0, length:0x
0, async:0x1, handle:0x3C4, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Service
s\WinSock2\Parameters\Protocol_Catalog9"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Serial_Access_Num", class:0x2, length:0x90, resultlength:0x10, handle:0x3C4,
path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Proto
col_Catalog9"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Servi
ces\WinSock2\Parameters\Protocol_Catalog9\00000009"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\WOW6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9
F9D}"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Next_Catalog_Entry_ID", class:0x2, length:0x90, resultlength:0x10, handle:0x
3C4, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\P
rotocol_Catalog9"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Num_Catalog_Entries", class:0x2, length:0x90, resultlength:0x10, handle:0x3C
4, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Pro
tocol_Catalog9"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"", class:0x2, length:0x90, resultlength:0x3C, handle:0x3FA, path:"\REGISTRY\
MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D
}"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D
}\InProcServer32"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x4
0C
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0xD8, handle:0x406, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\InProcServe
r32"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x40C, access:0x20019, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Wi
nSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x406, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\InProcServer32
"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0x8000
0005, name:"PackedCatalogItem", class:0x2, length:0x90, resultlength:0x384, hand
le:0x40C, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Paramet
ers\Protocol_Catalog9\Catalog_Entries\000000000006"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"PackedCatalogItem", class:0x2, length:0x384, resultlength:0x384, handle:0x40
C, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Pro
tocol_Catalog9\Catalog_Entries\000000000006"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x4
0C
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\WOW6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9
F9D}\InProcServer32"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"", class:0x2, length:0x90, resultlength:0x50, handle:0x406, path:"\REGISTRY\
MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D
}\InProcServer32"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x40C, access:0x20019, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Wi
nSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0xD8, handle:0x406, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\InProcServe
r32"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0x8000
0005, name:"PackedCatalogItem", class:0x2, length:0x90, resultlength:0x384, hand
le:0x40C, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Paramet
ers\Protocol_Catalog9\Catalog_Entries\000000000007"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x406, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\InProcServer32
"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"PackedCatalogItem", class:0x2, length:0x384, resultlength:0x384, handle:0x40
C, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Pro
tocol_Catalog9\Catalog_Entries\000000000007"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
\Classes\WOW6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtNotifyChangeKey, status:0x103
, event:0x3FC, iostatus:0x103, information:0x0, filter:0x1, watch:0x0, length:0x
0, async:0x1, handle:0x40C, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Service
s\WinSock2\Parameters\NameSpace_Catalog5"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Serial_Access_Num", class:0x2, length:0x90, resultlength:0x10, handle:0x40C,
path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameS
pace_Catalog5"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Servi
ces\WinSock2\Parameters\NameSpace_Catalog5\00000014"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Num_Catalog_Entries", class:0x2, length:0x90, resultlength:0x10, handle:0x40
C, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Nam
eSpace_Catalog5"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_Classes\WOW6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\I
nprocHandler"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x414, access:0x2000000, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\
WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\C
LSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\InprocHandler"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x418, access:0x20019, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Wi
nSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x3
FA
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"LibraryPath", class:0x2, length:0x90, resultlength:0x50, handle:0x418, path:
"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_C
atalog5\Catalog_Entries\000000000001"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"LibraryPath", class:0x2, length:0x90, resultlength:0x50, handle:0x418, path:
"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_C
atalog5\Catalog_Entries\000000000001"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"DisplayString", class:0x2, length:0x90, resultlength:0x5E, handle:0x418, pat
h:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace
_Catalog5\Catalog_Entries\000000000001"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"DisplayString", class:0x2, length:0x90, resultlength:0x5E, handle:0x418, pat
h:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace
_Catalog5\Catalog_Entries\000000000001"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x3F8, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\OLE"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"DisplayString", class:0x2, length:0x90, resultlength:0x5E, handle:0x418, pat
h:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace
_Catalog5\Catalog_Entries\000000000001"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"DisplayString", class:0x2, length:0x90, resultlength:0x5E, handle:0x418, pat
h:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace
_Catalog5\Catalog_Entries\000000000001"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"MaxSxSHashCount", class:0x2, length:0x90, resultlength:0x0, handle:0
x3F8, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\OLE"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ProviderId", class:0x2, length:0x90, resultlength:0x1C, handle:0x418, path:"
\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_Ca
talog5\Catalog_Entries\000000000001"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x3
F8
pid:4092, tid:4644, tick:0x33D6FF0, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"AddressFamily", class:0x2, length:0x90, resultlength:0x201CC, handle
:0x418, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameter
s\NameSpace_Catalog5\Catalog_Entries\000000000001"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"SupportedNameSpace", class:0x2, length:0x90, resultlength:0x10, handle:0x418
, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Name
Space_Catalog5\Catalog_Entries\000000000001"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Enabled", class:0x2, length:0x90, resultlength:0x10, handle:0x418, path:"\RE
GISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_Catal
og5\Catalog_Entries\000000000001"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Version", class:0x2, length:0x90, resultlength:0x10, handle:0x418, path:"\RE
GISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_Catal
og5\Catalog_Entries\000000000001"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x3F8, c
lass:0x14, length:0x4, returnlength:0x4
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"StoresServiceClassInfo", class:0x2, length:0x90, resultlength:0x10, handle:0
x418, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\
NameSpace_Catalog5\Catalog_Entries\000000000001"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x3F8, c
lass:0x1A, length:0x4, returnlength:0x4
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ProviderInfo", class:0x2, length:0x90, resultlength:0xC, handle:0x418, path:
"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_C
atalog5\Catalog_Entries\000000000001"
pid:4092, tid:2168, tick:0x33D6FF0, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x3F8, c
lass:0x1, length:0x64, returnlength:0x24, sid:"S-1-5-21-2360094602-2602383397-24
63990887-1001", attributes:0x0
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ProviderInfo", class:0x2, length:0x90, resultlength:0xC, handle:0x418, path:
"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_C
atalog5\Catalog_Entries\000000000001"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtClose, status:0x0, handle:0x4
18
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x418, access:0x20019, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Wi
nSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"LibraryPath", class:0x2, length:0x90, resultlength:0x50, handle:0x418, path:
"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_C
atalog5\Catalog_Entries\000000000002"
pid:4092, tid:4644, tick:0x33D6FF0, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"LibraryPath", class:0x2, length:0x90, resultlength:0x50, handle:0x418, path:
"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_C
atalog5\Catalog_Entries\000000000002"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"DisplayString", class:0x2, length:0x90, resultlength:0x5E, handle:0x418, pat
h:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace
_Catalog5\Catalog_Entries\000000000002"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x420, access:0x2000000, path:"\Registry\User\S-1-5-21-2360094602-2602383397-2463
990887-1001_Classes"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"DisplayString", class:0x2, length:0x90, resultlength:0x5E, handle:0x418, pat
h:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace
_Catalog5\Catalog_Entries\000000000002"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x3
F8
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"DisplayString", class:0x2, length:0x90, resultlength:0x5E, handle:0x418, pat
h:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace
_Catalog5\Catalog_Entries\000000000002"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"DisplayString", class:0x2, length:0x90, resultlength:0x5E, handle:0x418, pat
h:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace
_Catalog5\Catalog_Entries\000000000002"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ProviderId", class:0x2, length:0x90, resultlength:0x1C, handle:0x418, path:"
\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_Ca
talog5\Catalog_Entries\000000000002"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"AddressFamily", class:0x2, length:0x90, resultlength:0x201CC, handle
:0x418, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameter
s\NameSpace_Catalog5\Catalog_Entries\000000000002"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"SupportedNameSpace", class:0x2, length:0x90, resultlength:0x10, handle:0x418
, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Name
Space_Catalog5\Catalog_Entries\000000000002"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Enabled", class:0x2, length:0x90, resultlength:0x10, handle:0x418, path:"\RE
GISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_Catal
og5\Catalog_Entries\000000000002"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Version", class:0x2, length:0x90, resultlength:0x10, handle:0x418, path:"\RE
GISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_Catal
og5\Catalog_Entries\000000000002"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"StoresServiceClassInfo", class:0x2, length:0x90, resultlength:0x10, handle:0
x418, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\
NameSpace_Catalog5\Catalog_Entries\000000000002"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ProviderInfo", class:0x2, length:0x90, resultlength:0xC, handle:0x418, path:
"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_C
atalog5\Catalog_Entries\000000000002"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ProviderInfo", class:0x2, length:0x90, resultlength:0xC, handle:0x418, path:
"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_C
atalog5\Catalog_Entries\000000000002"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
18
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x418, access:0x20019, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Wi
nSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
nSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"LibraryPath", class:0x2, length:0x90, resultlength:0x50, handle:0x418, path:
"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_C
atalog5\Catalog_Entries\000000000005"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x92, handle:0x422, path:"\Registry\User\S-1-5-21
-2360094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"LibraryPath", class:0x2, length:0x90, resultlength:0x50, handle:0x418, path:
"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_C
atalog5\Catalog_Entries\000000000005"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x422, path:"\Registry\User\S-1-5-21-23
60094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"DisplayString", class:0x2, length:0x90, resultlength:0x62, handle:0x418, pat
h:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace
_Catalog5\Catalog_Entries\000000000005"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"DisplayString", class:0x2, length:0x90, resultlength:0x62, handle:0x418, pat
h:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace
_Catalog5\Catalog_Entries\000000000005"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\Registry\User\S-1-5-21-2360094602-260238339
7-2463990887-1001_Classes\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"DisplayString", class:0x2, length:0x90, resultlength:0x62, handle:0x418, pat
h:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace
_Catalog5\Catalog_Entries\000000000005"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"DisplayString", class:0x2, length:0x90, resultlength:0x62, handle:0x418, pat
h:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace
_Catalog5\Catalog_Entries\000000000005"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x3F8, access:0x20019, path:"\Registry\Machine\Software\Classes\CLSID\{1F486A52
-3CB1-48FD-8F50-B8DC300D9F9D}"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ProviderId", class:0x2, length:0x90, resultlength:0x1C, handle:0x418, path:"
\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_Ca
talog5\Catalog_Entries\000000000005"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0xBA, handle:0x3FA, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x3FA, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"AddressFamily", class:0x2, length:0x90, resultlength:0x201CC, handle
:0x418, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameter
s\NameSpace_Catalog5\Catalog_Entries\000000000005"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"SupportedNameSpace", class:0x2, length:0x90, resultlength:0x10, handle:0x418
, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Name
Space_Catalog5\Catalog_Entries\000000000005"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
crosoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x00000000000
00003.db"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtOpenFile, status:0x0, handle:
0x434, access:0x100021, iostatus:0x0, information:0x1, share:0x5, options:0x60,
path:"C:\WINDOWS\SYSTEM32\winhttp.dll"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x2AD0000, zerobits:0x0, commitsize:0x0, offset:0x0, viewsize:0x8E000,
disposition:0x1, type:0x0, protect:0x2, handle:0x43C, path:"\Sessions\1\BaseName
dObjects\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39
C3FDA2}.2.ver0x0000000000000003.db"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtCreateSection, status:0x0, ha
ndle:0x440, access:0xF, pageattribs:0x10, sectionattribs:0x1000000, file:0x434
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtSetInformationProcess, status
:0x0, class:0xC, length:0x4
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x74760000, zerobits:0x0, commitsize:0x0, viewsize:0x9B000, disposition
:0x1, type:0x800000, protect:0x4, handle:0x440, path:"C:\WINDOWS\SYSTEM32\winhtt
p.dll"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x20, path:"C:\WINDOWS\SysWOW64\propsys.dll"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtSetInformationProcess, status
:0x0, class:0xC, length:0x4
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
40
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
34
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryFullAttributesFile, stat
us:0x0, allocsize:0x14B000, size:0x14AE48, attribs:0x20, path:"C:\WINDOWS\SysWOW
64\propsys.dll"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"winhttp.dll", handle:0x74760000
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74760000, name:"WinHttpCreateProxyResolver", ordinal:0x0,
address:0x7478EE00, image:0x0, caller:0x70307CF5
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74760000, name:"WinHttpGetProxyForUrlEx", ordinal:0x0, ad
dress:0x7478EC70, image:0x0, caller:0x70307D0B
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74760000, name:"WinHttpGetProxyResult", ordinal:0x0, addr
ess:0x747C0C00, image:0x0, caller:0x70307D22
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74760000, name:"WinHttpFreeProxyResult", ordinal:0x0, add
ress:0x74791F10, image:0x0, caller:0x70307D39
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74760000, name:"WinHttpCloseHandle", ordinal:0x0, address
:0x7477B3F0, image:0x0, caller:0x70307D50
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74760000, name:"WinHttpOpen", ordinal:0x0, address:0x7479
3AA0, image:0x0, caller:0x70307D67
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74760000, name:"WinHttpSetStatusCallback", ordinal:0x0, a
ddress:0x74777180, image:0x0, caller:0x70307D7E
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74760000, name:"WinHttpResetAutoProxy", ordinal:0x0, addr
ess:0x74799E70, image:0x0, caller:0x70307D95
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryFullAttributesFile, stat
us:0x0, allocsize:0x188000, size:0x187698, attribs:0x20, path:"C:\WINDOWS\system
32\propsys.dll"
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74760000, name:"WinHttpSetOption", ordinal:0x0, address:0
e:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\Sof
tware\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2E1D0F0, class:0x3, length:0x14
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2E1D0F0, class:0x3, length:0x14
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2E1D0F0, class:0x3, length:0x14
pid:4092, tid:4644, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"EnableSpdyDebugAsserts", class:0x2, length:0x90, resultlength:0x34,
handle:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-100
1\Software\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2E1D0F0, class:0x3, length:0x14
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2E1D0F0, class:0x3, length:0x14
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2E1D0F0, class:0x3, length:0x14
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2E1D0F0, class:0x3, length:0x14
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2E1D0F0, class:0x3, length:0x14
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2E1D0F0, class:0x3, length:0x14
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2E1D0F0, class:0x3, length:0x14
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2E1D0F0, class:0x3, length:0x14
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2E1D0F0, class:0x3, length:0x14
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2E1D0F0, class:0x3, length:0x14
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2E1D0F0, class:0x3, length:0x14
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2E1D0F0, class:0x3, length:0x14
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x404, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24639908
87-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2E1D0F0, class:0x3, length:0x14
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2E1D0F0, class:0x3, length:0x14
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2E1D0F0, class:0x3, length:0x14
pid:4092, tid:4644, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"EnableNpn", class:0x2, length:0x90, resultlength:0x29CFC50, handle:0
x404, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWA
RE\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2E1D0F0, class:0x3, length:0x14
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2E1D0F0, class:0x3, length:0x14
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
04
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2E1D0F0, class:0x3, length:0x14
pid:4092, tid:4644, tick:0x33D6FFF, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"ondemandconnroutehelper.dll", handle:0x72360000
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0xEF0000
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
04
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ShellState", class:0x2, length:0x90, resultlength:0x30, handle:0x444, path:"
\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\Software\Microsoft
\Windows\CurrentVersion\Explorer"
pid:4092, tid:9004, tick:0x33D6FFF, lvl:LOG, func:RecurseRegistryConfig, log:"Du
plicate regkey Connections will not be added as it is at lower layer."
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
44
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x404, access:0x20019, path:"\REGISTRY\MACHINE\System\CurrentControlSet\Service
s\Psched\Parameters\Winsock"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0x8000
0005, name:"Mapping", class:0x2, length:0x90, resultlength:0xA4, handle:0x404, p
ath:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Psched\Parameters\Winsock"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x444, access:0x1, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVe
rsion\Policies\Explorer"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0x8000
0005, name:"Mapping", class:0x2, length:0x90, resultlength:0xA4, handle:0x404, p
ath:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Psched\Parameters\Winsock"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"NoWebView", class:0x2, length:0x90, resultlength:0x19D9A8, handle:0x
444, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Windows\CurrentVersion\Policies\
Explorer"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Mapping", class:0x2, length:0xA4, resultlength:0xA4, handle:0x404, path:"\RE
GISTRY\MACHINE\SYSTEM\ControlSet001\Services\Psched\Parameters\Winsock"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
44
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
04
pid:4092, tid:9004, tick:0x33D6FFF, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0xEF0000, zerobits:0x0, commitsize:0x0, offset:0x220000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:9004, tick:0x33D6FFF, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5A0000
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x404, access:0x20019, path:"\REGISTRY\MACHINE\SYSTEM\CurrentControlSet\Service
s\Winsock\Setup Migration\Providers"
pid:4092, tid:9004, tick:0x33D6FFF, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5A0000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:9004, tick:0x33D6FFF, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0xEF0000
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x440, access:0x20019, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Wi
nsock\Setup Migration\Providers\Psched"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x44C, access:0x1, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVe
rsion\Policies\Explorer"
pid:4092, tid:9004, tick:0x33D6FFF, lvl:LOG, func:_FaultInValuesIf, log:"Duplica
te reg value SavedLegacySettings will not be added as it is at lower layer. type
: 0x1"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
dows\CurrentVersion\Explorer\Advanced"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:LOG, func:BaseThreadInitThunk, log:"New
thread started (via BaseThreadInitThunk) at address: 0x77C3C6D0, parameter: 0x76
52D8"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x404, access:0x20019, path:"\REGISTRY\MACHINE\System\CurrentControlSet\Service
s\Tcpip6\Parameters\Winsock"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ShowCompColor", class:0x2, length:0x90, resultlength:0x10, handle:0x460, pat
h:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Micros
oft\Windows\CurrentVersion\Explorer\Advanced"
pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:NtDeviceIoControlFile, status:
0x0, event:0x45C, iostatus:0x0, information:0x50, code:0x120007, inlen:0x30, out
len:0x8, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"HideFileExt", class:0x2, length:0x90, resultlength:0x10, handle:0x460, path:
"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsof
t\Windows\CurrentVersion\Explorer\Advanced"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"MinSockaddrLength", class:0x2, length:0x90, resultlength:0x10, handle:0x404,
path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip6\Parameters\Winsock
"
pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x
45C
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"DontPrettyPath", class:0x2, length:0x90, resultlength:0x10, handle:0x460, pa
th:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Micro
soft\Windows\CurrentVersion\Explorer\Advanced"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"MaxSockaddrLength", class:0x2, length:0x90, resultlength:0x10, handle:0x404,
path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip6\Parameters\Winsock
"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ShowInfoTip", class:0x2, length:0x90, resultlength:0x10, handle:0x460, path:
"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsof
t\Windows\CurrentVersion\Explorer\Advanced"
pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:NtDeviceIoControlFile, status:
0x0, event:0x45C, iostatus:0x0, information:0x50, code:0x120007, inlen:0x30, out
len:0x4, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"HideIcons", class:0x2, length:0x90, resultlength:0x10, handle:0x460, path:"\
REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\
Windows\CurrentVersion\Explorer\Advanced"
pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x
45C
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"UseDelayedAcceptance", class:0x2, length:0x90, resultlength:0x10, handle:0x4
04, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip6\Parameters\Wins
ock"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"MapNetDrvBtn", class:0x2, length:0x90, resultlength:0x10, handle:0x460, path
:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microso
ft\Windows\CurrentVersion\Explorer\Advanced"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
04
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"WebView", class:0x2, length:0x90, resultlength:0x10, handle:0x460, path:"\RE
GISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Wi
ndows\CurrentVersion\Explorer\Advanced"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:New_NtQueryInformationToken::<l
EGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\Software\Microsoft\W
indows\CurrentVersion\Internet Settings\Connections"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x92, handle:0x386, path:"\REGISTRY\USER\S-1-5-21
-2360094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, n
ame:"SavedLegacySettings", class:0x2, length:0x90, resultlength:0x44, handle:0x4
6C, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\Software
\Microsoft\Windows\CurrentVersion\Internet Settings\Connections"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x72470000, zerobits:0x0, commitsize:0x0, viewsize:0x8000, disposition:
0x1, type:0x800000, protect:0x4, handle:0x468, path:"C:\WINDOWS\SYSTEM32\WINNSI.
DLL"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x386, path:"\REGISTRY\USER\S-1-5-21-23
60094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, n
ame:"SavedLegacySettings", class:0x2, length:0x90, resultlength:0x44, handle:0x4
6C, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\Software
\Microsoft\Windows\CurrentVersion\Internet Settings\Connections"
pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x
46C
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001_Classes\SystemFileAssociations\.exe"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
68
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x474, access:0x20019, path:"\Registry\Machine\Software\Classes\SystemFileAssoc
iations\.exe"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
5C
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x80, handle:0x476, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\SystemFileAssociations\.exe"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x476, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\SystemFileAssociations\.exe"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x736A0000
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_Classes\SystemFileAssociations\.exe\ShellEx\IconHandler"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtDuplicateObject, status:0x0,
targethandle:0x468, access:0x0, inherit:0x0, options:0x2, handle:0xFFFFFFFE
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\SystemFileAss
ociations\.exe\ShellEx\IconHandler"
pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:NtCreateKey, status:0x0, handl
e:0x404, access:0x1, title:0x0, class:"", options:0x0, disposition:0x2, path:"\R
EGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\Software\Microsoft\W
indows\CurrentVersion\Internet Settings\Connections"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0x58, handle:0x472, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\exefile"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtDeviceIoControlFile, status:0
EGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\Software\Microsoft\W
indows\CurrentVersion\Internet Settings\Connections"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
6C
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\SystemFileAssociations\.exe"
pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:NtSetValueKey, status:0x0, nam
e:"SavedLegacySettings", index:0x0, type:0x3, size:0x38, handle:0x498, path:"\RE
GISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\Software\Microsoft\Wi
ndows\CurrentVersion\Internet Settings\Connections"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"BrowseInPlace", class:0x2, length:0x90, resultlength:0x0, handle:0x4
76, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\SystemFileAssociations\.exe"
pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x
498
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x80, handle:0x476, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\SystemFileAssociations\.exe"
pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x
404
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x476, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\SystemFileAssociations\.exe"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x498, iocompletion:0x38, handle:0x460
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x701C0000
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
6C
pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:LdrResolveDelayLoadedAPI, stat
us:0x0, module:0x701C0000
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_Classes\SystemFileAssociations\.exe\BrowseInPlace"
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x46C, iostatus:0x0, information:0x68, code:0x12000F, inlen:0x38, outl
en:0x38, handle:0x2F4, path:"\??\Nsi"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x72170000
pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:LdrResolveDelayLoadedAPI, stat
us:0x0, module:0x72170000
pid:4092, tid:8800, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
6C
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\SystemFileAss
ociations\.exe\BrowseInPlace"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:NtDuplicateObject, status:0x0,
targethandle:0x46C, access:0x0, inherit:0x0, options:0x2, handle:0xFFFFFFFE
pid:4092, tid:11200, tick:0x33D6FFF, lvl:OK, func:NtDuplicateObject, status:0x0,
targethandle:0x4A4, access:0x0, inherit:0x0, options:0x2, handle:0xFFFFFFFE
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0x52, handle:0x466, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\.exe"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
ARE\Classes\exefile"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x472, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\exefile"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DisableAutoProxyAuth", class:0x2, length:0x90, resultlength:0x1D4, h
andle:0x4D8, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Curr
entVersion\Internet Settings\WinHttp"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
D8
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\exefile"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"NeverShowExt", class:0x2, length:0x90, resultlength:0x0, handle:0x47
2, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\exefile"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x74760000
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0x80, handle:0x476, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\SystemFileAssociations\.exe"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"winhttp.dll", handle:0x74760000
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x476, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\SystemFileAssociations\.exe"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x74760000
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:WSAStartup, ret:0x0, gle:0x0, V
ersionRequested:0x101, Version:0x102, Description:"WinSock 2.0", SystemStatus:"R
unning", MaxSockets:0x7FFF, MaxUdpDg:0xFFBB
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"ondemandconnroutehelper.dll", handle:0x72360000
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\SystemFileAssociations\.exe"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x72360000, name:"GetInterfaceContextTableForHostName", ord
inal:0x0, address:0x72363490, image:0x0, caller:0x747925AB
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x72360000, name:"FreeInterfaceContextTable", ordinal:0x0,
address:0x72363D40, image:0x0, caller:0x747925C1
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"NeverShowExt", class:0x2, length:0x90, resultlength:0x0, handle:0x47
6, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\SystemFileAssociations\.exe"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x4DC, c
lass:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
66
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
DC
0, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion
\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"RelativePath", class:0x2, length:0x90, resultlength:0x1C, handle:0x4E0, path
:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explor
er\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x4E4, access:0x2000000, path:"\REGISTRY\MACHINE\SYSTEM\CurrentControlSet\Servi
ces\WinHttpAutoProxySvc\Parameters"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"ParsingName", class:0x2, length:0x90, resultlength:0x1C, handle:0x4E
0, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion
\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ProxyDllFile", class:0x2, length:0x90, resultlength:0x50, handle:0x4E4, path
:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinHttpAutoProxySvc\Parameters
"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"InfoTip", class:0x2, length:0x90, resultlength:0x1C, handle:0x4E0, p
ath:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Exp
lorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
E4
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"LocalizedName", class:0x2, length:0x90, resultlength:0x60, handle:0x4E0, pat
h:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explo
rer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Icon", class:0x2, length:0x90, resultlength:0x5C, handle:0x4E0, path:"\REGIS
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Folde
rDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x4E4, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\Curre
ntVersion\Internet Settings\WinHttp"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Security", class:0x2, length:0x90, resultlength:0x5C, handle:0x4E0,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Ex
plorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"AutoProxyAutoLogonIfChallenged", class:0x2, length:0x90, resultlengt
h:0x0, handle:0x4E4, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Wind
ows\CurrentVersion\Internet Settings\WinHttp"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
E4
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"StreamResource", class:0x2, length:0x90, resultlength:0x5C, handle:0
x4E0, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVers
ion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"StreamResourceType", class:0x2, length:0x90, resultlength:0x5C, hand
le:0x4E0, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Current
Version\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x4E4, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\windows\Curre
ntVersion\Internet Settings"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"LocalRedirectOnly", class:0x2, length:0x90, resultlength:0x5C, handl
e:0x4E0, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentV
ersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
ows_shell_global_counters"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x464, access:0x1, path:"\REGISTRY\MACHINE\Software\Policies\Microsoft\Windows\
CurrentVersion\Internet Settings\"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Security_HKLM_only", class:0x2, length:0x90, resultlength:0x1D4, han
dle:0x464, path:"\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVe
rsion\Internet Settings"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
64
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x4E0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\Curre
ntVersion\Explorer\FolderDescriptions"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_I
GNORE_POLICIES_ZONEMAP_IF_ESC_ENABLED_KB918915"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x504, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\W
indows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC
332AEAE}"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
E0
pid:4092, tid:1488, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft
\Internet Explorer\Main\FeatureControl\FEATURE_IGNORE_POLICIES_ZONEMAP_IF_ESC_EN
ABLED_KB918915"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Category", class:0x2, length:0x90, resultlength:0x10, handle:0x504, path:"\R
EGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\F
olderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Name", class:0x2, length:0x90, resultlength:0x20, handle:0x504, path:"\REGIS
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Folde
rDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ParentFolder", class:0x2, length:0x90, resultlength:0x5A, handle:0x504, path
:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explor
er\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies\Microsof
t\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Description", class:0x2, length:0x90, resultlength:0x5A, handle:0x50
4, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion
\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"RelativePath", class:0x2, length:0x90, resultlength:0x44, handle:0x504, path
:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explor
er\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"ParsingName", class:0x2, length:0x90, resultlength:0x44, handle:0x50
4, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion
\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"InfoTip", class:0x2, length:0x90, resultlength:0x44, handle:0x504, p
ath:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Exp
lorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Se
ttings\ZoneMap\Domains\"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"LocalizedName", class:0x2, length:0x90, resultlength:0x44, handle:0x
504, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersi
on\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Icon", class:0x2, length:0x90, resultlength:0x44, handle:0x504, path
:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explor
er\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Security", class:0x2, length:0x90, resultlength:0x44, handle:0x504,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Ex
plorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies\Microsof
t\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"StreamResource", class:0x2, length:0x90, resultlength:0x44, handle:0
x504, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVers
ion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"StreamResourceType", class:0x2, length:0x90, resultlength:0x44, hand
le:0x504, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Current
Version\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\ZoneMap\Ranges\"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"LocalRedirectOnly", class:0x2, length:0x90, resultlength:0x44, handl
e:0x504, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentV
ersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Roamable", class:0x2, length:0x90, resultlength:0x44, handle:0x504,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Ex
plorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"PreCreate", class:0x2, length:0x90, resultlength:0x10, handle:0x504, path:"\
REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\
FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001\ZoneMap\Ranges\"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Stream", class:0x2, length:0x90, resultlength:0x10, handle:0x504, pa
th:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Expl
orer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"PublishExpandedPath", class:0x2, length:0x90, resultlength:0x10, handle:0x50
4, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion
\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\ZoneMap\Ranges\"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DefinitionFlags", class:0x2, length:0x90, resultlength:0x10, handle:
0x504, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVer
sion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"ntdll.dll", module:0x77C10000
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Attributes", class:0x2, length:0x90, resultlength:0x10, handle:0x504
, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\
Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77C10000, name:"RtlGetDeviceFamilyInfoEnum", ordinal:0x0,
address:0x77C7B110, image:0x0, caller:0x72A1504F
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"FolderTypeID", class:0x2, length:0x90, resultlength:0x10, handle:0x5
04, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersio
n\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"InitFolderHandler", class:0x2, length:0x90, resultlength:0x10, handl
e:0x504, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentV
ersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Micro
soft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF
-BD1DC332AEAE}\PropertyBag"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_Z
ONES_CHECK_ZONEMAP_POLICY_KB941001"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x5
04
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x504, c
lass:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:1488, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft
\Internet Explorer\Main\FeatureControl\FEATURE_ZONES_CHECK_ZONEMAP_POLICY_KB9410
01"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x4E0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24639908
87-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\K
nownFolders"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
E0
pid:4092, tid:1488, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\Software\Policies\Microsoft\Wi
ndows\CurrentVersion\Internet Settings\ZoneMap"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:1488, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settin
gs\ZoneMap"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x49C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246399
0887-1001"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x4E4, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folder
s"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:NtCreateKey, status:0x0, handle
:0x520, access:0x2001F, title:0x0, class:"", options:0x0, disposition:0x2, path:
"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\Software\Microsof
t\Windows\CurrentVersion\Internet Settings\ZoneMap\"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
9C
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}", class:0x2, length:0x90, res
ultlength:0x0, handle:0x4E4, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397
-2463990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell F
olders"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x528, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\Curre
ntVersion\Internet Settings\ZoneMap\"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x4E0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\Curre
ntVersion\Explorer\FolderDescriptions"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Se
ttings\ZoneMap\"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x49C, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\W
indows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF6
5729F3D}"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x4
E0
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Category", class:0x2, length:0x90, resultlength:0x10, handle:0x49C, path:"\R
EGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\F
olderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies\Microsof
t\Windows\CurrentVersion\Internet Settings\ZoneMap\"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Name", class:0x2, length:0x90, resultlength:0x1C, handle:0x49C, path:"\REGIS
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Folde
rDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"ParentFolder", class:0x2, length:0x90, resultlength:0x10, handle:0x4
9C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersio
n\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Description", class:0x2, length:0x90, resultlength:0x10, handle:0x49
C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion
\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies\Microsof
t\Windows\CurrentVersion\Internet Settings\ZoneMap\"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"RelativePath", class:0x2, length:0x90, resultlength:0x2C, handle:0x49C, path
:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explor
er\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"ParsingName", class:0x2, length:0x90, resultlength:0x2C, handle:0x49
C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion
\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"InfoTip", class:0x2, length:0x90, resultlength:0x2C, handle:0x49C, p
ath:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Exp
lorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\Software\Policies\Microsoft\Internet Explorer"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"LocalizedName", class:0x2, length:0x90, resultlength:0x2C, handle:0x
49C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersi
on\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Icon", class:0x2, length:0x90, resultlength:0x2C, handle:0x49C, path
:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explor
er\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Security", class:0x2, length:0x90, resultlength:0x2C, handle:0x49C,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Ex
plorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x524, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Internet Explorer\Security"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"StreamResource", class:0x2, length:0x90, resultlength:0x2C, handle:0
x49C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVers
ion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"StreamResourceType", class:0x2, length:0x90, resultlength:0x2C, hand
le:0x49C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Current
Version\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DisableSecuritySettingsCheck", class:0x2, length:0x90, resultlength:
0x0, handle:0x524, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246399088
7-1001\SOFTWARE\Microsoft\Internet Explorer\Security"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"LocalRedirectOnly", class:0x2, length:0x90, resultlength:0x2C, handl
e:0x49C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentV
ersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:NtClose, status:0x0, handle:0x5
24
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Roamable", class:0x2, length:0x90, resultlength:0x2C, handle:0x49C,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Ex
plorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"PreCreate", class:0x2, length:0x90, resultlength:0x2C, handle:0x49C,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\E
xplorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}"
pid:4092, tid:2168, tick:0x33D6FFF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Stream", class:0x2, length:0x90, resultlength:0x2C, handle:0x49C, pa
th:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Expl
orer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}"
pid:4092, tid:1488, tick:0x33D6FFF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x524, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Internet Expl
orer\Security"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"PublishExpandedPath", class:0x2, length:0x90, resultlength:0x2C, han
dle:0x49C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Curren
tVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DisableSecuritySettingsCheck", class:0x2, length:0x90, resultlength:
0x0, handle:0x524, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Intern
et Explorer\Security"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DefinitionFlags", class:0x2, length:0x90, resultlength:0x2C, handle:
0x49C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVer
sion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
24
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Attributes", class:0x2, length:0x90, resultlength:0x2C, handle:0x49C
, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\
Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x7361B000, class:0x0, length:0x1C, resultlength:0x1C
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"FolderTypeID", class:0x2, length:0x90, resultlength:0x2C, handle:0x4
9C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersio
n\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"SspiCli.dll", handle:0x74940000
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74940000, name:"GetUserNameExW", ordinal:0x0, address:0x7
494C5F0, image:0x0, caller:0x735747A8
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"InitFolderHandler", class:0x2, length:0x90, resultlength:0x2C, handl
e:0x49C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentV
ersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Micro
soft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A
-E3EF65729F3D}\PropertyBag"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x4
9C
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x49C, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24639908
87-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtCreateSection, status:0x40000
000, handle:0x524, access:0xF0007, size:0x1C, pageattribs:0x4, sectionattribs:0x
8000000, path:"\Sessions\1\BaseNamedObjects\Local\UrlZonesSM_i92segoa"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\K
nownFolders"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x3750000, zerobits:0x0, commitsize:0x0, offset:0x0, viewsize:0x1000, d
isposition:0x1, type:0x0, protect:0x4, handle:0x524, path:"\Sessions\1\BaseNamed
Objects\UrlZonesSM_i92segoa"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x4
9C
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x52C, access:0x20019, path:"\REGISTRY\MACHINE\System\Setup"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"AppData", class:0x2, length:0x90, resultlength:0x48, handle:0x4E4, path:"\RE
GISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Wi
ndows\CurrentVersion\Explorer\User Shell Folders"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"SystemSetupInProgress", class:0x2, length:0x90, resultlength:0x10, handle:0x
52C, path:"\REGISTRY\MACHINE\SYSTEM\Setup"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
2C
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x52C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
04
er\FolderDescriptions\{F42EE2D3-909F-4907-8871-4C22FC0BF756}"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0x8000
0005, name:"ParsingName", class:0x2, length:0x90, resultlength:0xBC, handle:0x53
0, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion
\Explorer\FolderDescriptions\{F42EE2D3-909F-4907-8871-4C22FC0BF756}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Se
ttings\Zones\"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ParsingName", class:0x2, length:0xBC, resultlength:0xBC, handle:0x530, path:
"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explore
r\FolderDescriptions\{F42EE2D3-909F-4907-8871-4C22FC0BF756}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies\Microsof
t\Windows\CurrentVersion\Internet Settings\Zones\"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"InfoTip", class:0x2, length:0x90, resultlength:0xBC, handle:0x530, p
ath:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Exp
lorer\FolderDescriptions\{F42EE2D3-909F-4907-8871-4C22FC0BF756}"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"LocalizedName", class:0x2, length:0x90, resultlength:0x60, handle:0x530, pat
h:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explo
rer\FolderDescriptions\{F42EE2D3-909F-4907-8871-4C22FC0BF756}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Se
ttings\Zones\"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Icon", class:0x2, length:0x90, resultlength:0x5C, handle:0x530, path:"\REGIS
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Folde
rDescriptions\{F42EE2D3-909F-4907-8871-4C22FC0BF756}"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Security", class:0x2, length:0x90, resultlength:0x5C, handle:0x530,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Ex
plorer\FolderDescriptions\{F42EE2D3-909F-4907-8871-4C22FC0BF756}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies\Microsof
t\Windows\CurrentVersion\Internet Settings\Zones\"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"StreamResource", class:0x2, length:0x90, resultlength:0x5C, handle:0
x530, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVers
ion\Explorer\FolderDescriptions\{F42EE2D3-909F-4907-8871-4C22FC0BF756}"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"StreamResourceType", class:0x2, length:0x90, resultlength:0x5C, hand
le:0x530, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Current
Version\Explorer\FolderDescriptions\{F42EE2D3-909F-4907-8871-4C22FC0BF756}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x52C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"LocalRedirectOnly", class:0x2, length:0x90, resultlength:0x5C, handl
e:0x530, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentV
ersion\Explorer\FolderDescriptions\{F42EE2D3-909F-4907-8871-4C22FC0BF756}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x0, class:0x0, length:0x120, resultlength:0x12, handle:0x52C, path:"\REGISTR
Y\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Windows
\CurrentVersion\Internet Settings\Zones"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Roamable", class:0x2, length:0x90, resultlength:0x5C, handle:0x530,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Ex
plorer\FolderDescriptions\{F42EE2D3-909F-4907-8871-4C22FC0BF756}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtCreateMutant, status:0x400000
00, handle:0x534, access:0x1F0001, owner:0x0, path:"\Sessions\1\BaseNamedObjects
\Local\ZonesCacheCounterMutex"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"PreCreate", class:0x2, length:0x90, resultlength:0x10, handle:0x530, path:"\
REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\
FolderDescriptions\{F42EE2D3-909F-4907-8871-4C22FC0BF756}"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Stream", class:0x2, length:0x90, resultlength:0x10, handle:0x530, pa
th:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Expl
orer\FolderDescriptions\{F42EE2D3-909F-4907-8871-4C22FC0BF756}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x53C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"PublishExpandedPath", class:0x2, length:0x90, resultlength:0x10, han
dle:0x530, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Curren
tVersion\Explorer\FolderDescriptions\{F42EE2D3-909F-4907-8871-4C22FC0BF756}"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DefinitionFlags", class:0x2, length:0x90, resultlength:0x10, handle:
0x530, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVer
sion\Explorer\FolderDescriptions\{F42EE2D3-909F-4907-8871-4C22FC0BF756}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies\Microsof
t\Windows\CurrentVersion\Internet Settings\Zones\0"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Attributes", class:0x2, length:0x90, resultlength:0x10, handle:0x530, path:"
\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer
\FolderDescriptions\{F42EE2D3-909F-4907-8871-4C22FC0BF756}"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"FolderTypeID", class:0x2, length:0x90, resultlength:0x10, handle:0x5
30, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersio
n\Explorer\FolderDescriptions\{F42EE2D3-909F-4907-8871-4C22FC0BF756}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Se
ttings\Zones\0"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"InitFolderHandler", class:0x2, length:0x90, resultlength:0x10, handl
e:0x530, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentV
ersion\Explorer\FolderDescriptions\{F42EE2D3-909F-4907-8871-4C22FC0BF756}"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x4E4, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\W
indows\CurrentVersion\Explorer\FolderDescriptions\{F42EE2D3-909F-4907-8871-4C22F
C0BF756}\PropertyBag"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies\Microsof
t\Windows\CurrentVersion\Internet Settings\Zones\0"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
30
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x530, c
lass:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x540, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Flags", class:0x2, length:0x90, resultlength:0x10, handle:0x540, path:"\REGI
STRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Wind
ows\CurrentVersion\Internet Settings\Zones\0"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x538, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24639908
87-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
40
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
3C
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\K
nownFolders"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
38
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1, class:0x0, length:0x120, resultlength:0x12, handle:0x52C, path:"\REGISTR
Y\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Windows
\CurrentVersion\Internet Settings\Zones"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x540, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies\Microsof
t\Windows\CurrentVersion\Internet Settings\Zones\1"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x53C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246399
0887-1001"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Se
ttings\Zones\1"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x544, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folder
s"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies\Microsof
t\Windows\CurrentVersion\Internet Settings\Zones\1"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
3C
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"{F42EE2D3-909F-4907-8871-4C22FC0BF756}", class:0x2, length:0x90, res
ultlength:0x0, handle:0x544, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397
-2463990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell F
olders"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x548, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x538, c
lass:0x1, length:0x40, returnlength:0x24, sid:"S-1-5-21-2360094602-2602383397-24
63990887-1001", attributes:0x0
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Flags", class:0x2, length:0x90, resultlength:0x10, handle:0x548, path:"\REGI
STRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Wind
ows\CurrentVersion\Internet Settings\Zones\1"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x53C, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows NT\Cu
rrentVersion\ProfileList\S-1-5-21-2360094602-2602383397-2463990887-1001"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x54C, access:0x2001F, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\
"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ProfileImagePath", class:0x2, length:0x90, resultlength:0x30, handle:0x53C,
path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\ProfileList
\S-1-5-21-2360094602-2602383397-2463990887-1001"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtSetValueKey, status:0x0, name
:"ProxyBypass", index:0x0, type:0x4, size:0x4, handle:0x54C, path:"\REGISTRY\USE
R\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Windows\Curr
entVersion\Internet Settings\ZoneMap"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ProfileImagePath", class:0x2, length:0x90, resultlength:0x30, handle:0x53C,
path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\ProfileList
\S-1-5-21-2360094602-2602383397-2463990887-1001"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
3C
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtSetValueKey, status:0x0, name
:"IntranetName", index:0x0, type:0x4, size:0x4, handle:0x54C, path:"\REGISTRY\US
ER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Windows\Cur
rentVersion\Internet Settings\ZoneMap"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
38
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
30
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtSetValueKey, status:0x0, name
:"UNCAsIntranet", index:0x0, type:0x4, size:0x4, handle:0x54C, path:"\REGISTRY\U
SER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Windows\Cu
rrentVersion\Internet Settings\ZoneMap"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
44
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtSetValueKey, status:0x0, name
:"AutoDetect", index:0x0, type:0x4, size:0x4, handle:0x54C, path:"\REGISTRY\USER
\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Windows\Curre
ntVersion\Internet Settings\ZoneMap"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
4C
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
48
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
40
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x2, class:0x0, length:0x120, resultlength:0x12, handle:0x52C, path:"\REGISTR
Y\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Windows
\CurrentVersion\Internet Settings\Zones"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x3760000, zerobits:0x0, commitsize:0x0, offset:0x1E0000, viewsize:0x10
000, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5A0000
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding directory Portalbe firefox with flags: 6."
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x540, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2"
30
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x530, c
lass:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies\Microsof
t\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x538, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24639908
87-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Se
ttings\Lockdown_Zones\"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\K
nownFolders"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
38
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies\Microsof
t\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x52C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown
_Zones\"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x0, class:0x0, length:0x120, resultlength:0x12, handle:0x52C, path:"\REGISTR
Y\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Windows
\CurrentVersion\Internet Settings\Lockdown_Zones"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x53C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246399
0887-1001"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtCreateMutant, status:0x400000
00, handle:0x540, access:0x1F0001, owner:0x0, path:"\Sessions\1\BaseNamedObjects
\Local\ZonesLockedCacheCounterMutex"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x550, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folder
s"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x548, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown
_Zones\0"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
3C
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies\Microsof
t\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"{A0C69A99-21C8-4671-8703-7934162FCF1D}", class:0x2, length:0x90, res
ultlength:0x0, handle:0x550, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397
-2463990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell F
olders"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:New_NtQueryInformationToken::<l
0, address:0x3760000
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Se
ttings\Lockdown_Zones\1"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x3760000, zerobits:0x0, commitsize:0x0, offset:0x1E0000, viewsize:0x10
000, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5A0000
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies\Microsof
t\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5A0000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x3760000
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x554, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Flags", class:0x2, length:0x90, resultlength:0x10, handle:0x554, path:"\REGI
STRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Wind
ows\CurrentVersion\Internet Settings\Zones\1"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x558, access:0x2001F, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\
"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtSetValueKey, status:0x0, name
:"ProxyBypass", index:0x0, type:0x4, size:0x4, handle:0x558, path:"\REGISTRY\USE
R\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Windows\Curr
entVersion\Internet Settings\ZoneMap"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtCreateFile, status:0x0, handl
e:0x550, access:0x80100080, iostatus:0x0, information:0x1, attribs:0x0, share:0x
7, disposition:0x1, options:0x64, path:"C:\Users\i92segoa\Music\desktop.ini"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryInformationFile, status:
0x0, iostatus:0x0, information:0x18, length:0x18, class:0x5, handle:0x550, path:
"C:\Users\i92segoa\Music\desktop.ini"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtSetValueKey, status:0x0, name
:"IntranetName", index:0x0, type:0x4, size:0x4, handle:0x558, path:"\REGISTRY\US
ER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Windows\Cur
rentVersion\Internet Settings\ZoneMap"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtReadFile, status:0x0, iostatu
s:0x0, information:0x1F8, length:0x1FA, handle:0x550, path:"C:\Users\i92segoa\Mu
sic\desktop.ini"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtSetValueKey, status:0x0, name
:"UNCAsIntranet", index:0x0, type:0x4, size:0x4, handle:0x558, path:"\REGISTRY\U
SER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Windows\Cu
rrentVersion\Internet Settings\ZoneMap"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryInformationFile, status:
0x0, iostatus:0x0, information:0x28, length:0x28, class:0x4, handle:0x550, path:
"C:\Users\i92segoa\Music\desktop.ini"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
50
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtSetValueKey, status:0x0, name
:"AutoDetect", index:0x0, type:0x4, size:0x4, handle:0x558, path:"\REGISTRY\USER
\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Windows\Curre
ntVersion\Internet Settings\ZoneMap"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
58
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
54
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
48
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x2, class:0x0, length:0x120, resultlength:0x12, handle:0x52C, path:"\REGISTR
Y\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Windows
\CurrentVersion\Internet Settings\Lockdown_Zones"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x550, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\Curre
ntVersion\Explorer\FolderDescriptions"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x530, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\W
indows\CurrentVersion\Explorer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F5971
3854639}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x548, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown
_Zones\2"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
50
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Category", class:0x2, length:0x90, resultlength:0x10, handle:0x530, path:"\R
EGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\F
olderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies\Microsof
t\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Name", class:0x2, length:0x90, resultlength:0x2A, handle:0x530, path:"\REGIS
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Folde
rDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"ParentFolder", class:0x2, length:0x90, resultlength:0x10, handle:0x5
30, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersio
n\Explorer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Se
ttings\Lockdown_Zones\2"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Description", class:0x2, length:0x90, resultlength:0x10, handle:0x53
0, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion
\Explorer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"RelativePath", class:0x2, length:0x90, resultlength:0x1E, handle:0x530, path
:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explor
er\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies\Microsof
t\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0x8000
0005, name:"ParsingName", class:0x2, length:0x90, resultlength:0xBC, handle:0x53
0, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion
\Explorer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ParsingName", class:0x2, length:0xBC, resultlength:0xBC, handle:0x530, path:
"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explore
r\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}"
7-2463990887-1001\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Se
ttings\Lockdown_Zones\3"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Stream", class:0x2, length:0x90, resultlength:0x10, handle:0x530, pa
th:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Expl
orer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"PublishExpandedPath", class:0x2, length:0x90, resultlength:0x10, han
dle:0x530, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Curren
tVersion\Explorer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies\Microsof
t\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DefinitionFlags", class:0x2, length:0x90, resultlength:0x10, handle:
0x530, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVer
sion\Explorer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Attributes", class:0x2, length:0x90, resultlength:0x10, handle:0x530, path:"
\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer
\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x554, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"FolderTypeID", class:0x2, length:0x90, resultlength:0x10, handle:0x5
30, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersio
n\Explorer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Flags", class:0x2, length:0x90, resultlength:0x10, handle:0x554, path:"\REGI
STRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Wind
ows\CurrentVersion\Internet Settings\Zones\3"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
54
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"InitFolderHandler", class:0x2, length:0x90, resultlength:0x10, handl
e:0x530, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentV
ersion\Explorer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
48
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x550, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\W
indows\CurrentVersion\Explorer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F5971
3854639}\PropertyBag"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x4, class:0x0, length:0x120, resultlength:0x12, handle:0x52C, path:"\REGISTR
Y\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Windows
\CurrentVersion\Internet Settings\Lockdown_Zones"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
30
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x530, c
lass:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x548, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown
_Zones\4"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x538, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24639908
87-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1"
path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\ProfileList
\S-1-5-21-2360094602-2602383397-2463990887-1001"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"CreateUriCacheSize", class:0x2, length:0x90, resultlength:0x680000,
handle:0x3E4, path:"\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\Curren
tVersion\Internet Settings"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ProfileImagePath", class:0x2, length:0x90, resultlength:0x30, handle:0x53C,
path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\ProfileList
\S-1-5-21-2360094602-2602383397-2463990887-1001"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
3C
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"CreateUriCacheSize", class:0x2, length:0x90, resultlength:0x680000,
handle:0x3A8, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-100
1\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
38
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
30
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"CreateUriCacheSize", class:0x2, length:0x90, resultlength:0x680000,
handle:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-100
1\Software\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
4C
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"CreateUriCacheSize", class:0x2, length:0x90, resultlength:0x680000,
handle:0x3F4, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Cur
rentVersion\Internet Settings"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"EnablePunycode", class:0x2, length:0x90, resultlength:0x1264920, han
dle:0x3E4, path:"\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVe
rsion\Internet Settings"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x3760000, zerobits:0x0, commitsize:0x0, offset:0x1E0000, viewsize:0x10
000, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"EnablePunycode", class:0x2, length:0x90, resultlength:0x1264920, han
dle:0x3A8, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\S
OFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5A0000
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"EnablePunycode", class:0x2, length:0x90, resultlength:0x1264920, han
dle:0x370, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\S
oftware\Microsoft\Windows\CurrentVersion\Internet Settings"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5A0000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"EnablePunycode", class:0x2, length:0x90, resultlength:0x10, handle:0x3F4, pa
th:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Inte
rnet Settings"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x3760000
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_A
LLOW_REVERSE_SOLIDUS_IN_USERINFO_KB932562"
Internet Settings\ZoneMap\Domains"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ProxyBypass", class:0x2, length:0x90, resultlength:0x10, handle:0x520, path:
"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsof
t\Windows\CurrentVersion\Internet Settings\ZoneMap"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"StreamResource", class:0x2, length:0x90, resultlength:0x5C, handle:0
x530, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVers
ion\Explorer\FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}"
pid:4092, tid:8264, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
14
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x701C0000, name:"IsHostInProxyBypassList", ordinal:0x0, ad
dress:0x702C22D0, image:0x0, caller:0x735747A8
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"StreamResourceType", class:0x2, length:0x90, resultlength:0x5C, hand
le:0x530, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Current
Version\Explorer\FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"LocalRedirectOnly", class:0x2, length:0x90, resultlength:0x5C, handl
e:0x530, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentV
ersion\Explorer\FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}"
pid:4092, tid:8264, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows
\CurrentVersion\Internet Settings\ZoneMap\Domains\"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
48
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Roamable", class:0x2, length:0x90, resultlength:0x5C, handle:0x530,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Ex
plorer\FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}"
pid:4092, tid:8264, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"AutoDetect", class:0x2, length:0x90, resultlength:0x10, handle:0x520, path:"
\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft
\Windows\CurrentVersion\Internet Settings\ZoneMap"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"PreCreate", class:0x2, length:0x90, resultlength:0x10, handle:0x530, path:"\
REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\
FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x548, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\
ProtocolDefaults\"
pid:4092, tid:8264, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"IntranetName", class:0x2, length:0x90, resultlength:0x10, handle:0x520, path
:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microso
ft\Windows\CurrentVersion\Internet Settings\ZoneMap"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Stream", class:0x2, length:0x90, resultlength:0x10, handle:0x530, pa
th:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Expl
orer\FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtQueryKey, status:0x0, class:0
x4, length:0xB0, resultlength:0x28, handle:0x548, path:"\REGISTRY\USER\S-1-5-212360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\
Internet Settings\ZoneMap\ProtocolDefaults"
pid:4092, tid:8264, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ProxyBypass", class:0x2, length:0x90, resultlength:0x10, handle:0x520, path:
"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsof
t\Windows\CurrentVersion\Internet Settings\ZoneMap"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
ISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Win
dows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
48
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x754E0000, ordinal:0x6, address:0x754FAC10, image:0x0, cal
ler:0x735747A8
pid:4092, tid:8264, tick:0x33D700F, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x754E0000, ordinal:0x6, address:0x754FAC10, image:0x0, cal
ler:0x735747A8
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x538, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24639908
87-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\K
nownFolders"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
38
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x548, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"1A10", class:0x2, length:0x90, resultlength:0x331F654, handle:0x548,
path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Mi
crosoft\Windows\CurrentVersion\Internet Settings\Zones\3"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x464, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\Curre
ntVersion\Internet Settings\Zones\3"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x53C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246399
0887-1001"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"1A10", class:0x2, length:0x90, resultlength:0x10, handle:0x464, path:"\REGIS
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Internet Setti
ngs\Zones\3"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
48
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x4
64
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x52C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folder
s"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
3C
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"{35286A68-3C57-41A1-BBB1-0EAE73D76C95}", class:0x2, length:0x90, res
ultlength:0x0, handle:0x52C, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397
-2463990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell F
olders"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x538, c
lass:0x1, length:0x40, returnlength:0x24, sid:"S-1-5-21-2360094602-2602383397-24
63990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\
Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"FolderTypeID", class:0x2, length:0x90, resultlength:0x48, handle:0x5
5C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersio
n\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"InitFolderHandler", class:0x2, length:0x90, resultlength:0x48, handl
e:0x55C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentV
ersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Micro
soft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E
-08A611B84FF6}\PropertyBag"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
5C
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x55C, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24639908
87-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x548, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\Curre
ntVersion\Explorer\FolderDescriptions"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\K
nownFolders"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
5C
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x530, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\W
indows\CurrentVersion\Explorer\FolderDescriptions\{A52BBA46-E9E1-435F-B3D9-28DAA
648C0F6}"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
48
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Category", class:0x2, length:0x90, resultlength:0x10, handle:0x530, path:"\R
EGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\F
olderDescriptions\{A52BBA46-E9E1-435F-B3D9-28DAA648C0F6}"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Name", class:0x2, length:0x90, resultlength:0x1E, handle:0x530, path:"\REGIS
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Folde
rDescriptions\{A52BBA46-E9E1-435F-B3D9-28DAA648C0F6}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x558, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246399
0887-1001"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ParentFolder", class:0x2, length:0x90, resultlength:0x5A, handle:0x530, path
:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explor
er\FolderDescriptions\{A52BBA46-E9E1-435F-B3D9-28DAA648C0F6}"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Description", class:0x2, length:0x90, resultlength:0x5A, handle:0x53
0, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion
\Explorer\FolderDescriptions\{A52BBA46-E9E1-435F-B3D9-28DAA648C0F6}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x564, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folder
s"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"RelativePath", class:0x2, length:0x90, resultlength:0x1E, handle:0x530, path
:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explor
er\FolderDescriptions\{A52BBA46-E9E1-435F-B3D9-28DAA648C0F6}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
58
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ParsingName", class:0x2, length:0x90, resultlength:0x6A, handle:0x530, path:
"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explore
r\FolderDescriptions\{A52BBA46-E9E1-435F-B3D9-28DAA648C0F6}"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"InfoTip", class:0x2, length:0x90, resultlength:0x6A, handle:0x530, p
ath:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Exp
lorer\FolderDescriptions\{A52BBA46-E9E1-435F-B3D9-28DAA648C0F6}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Cookies", class:0x2, length:0x90, resultlength:0x88, handle:0x564, path:"\RE
GISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Wi
ndows\CurrentVersion\Explorer\User Shell Folders"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"LocalizedName", class:0x2, length:0x90, resultlength:0x6E, handle:0x530, pat
h:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explo
rer\FolderDescriptions\{A52BBA46-E9E1-435F-B3D9-28DAA648C0F6}"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Icon", class:0x2, length:0x90, resultlength:0x5E, handle:0x530, path:"\REGIS
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Folde
rDescriptions\{A52BBA46-E9E1-435F-B3D9-28DAA648C0F6}"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Security", class:0x2, length:0x90, resultlength:0x5E, handle:0x530,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Ex
plorer\FolderDescriptions\{A52BBA46-E9E1-435F-B3D9-28DAA648C0F6}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
54
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
64
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"StreamResource", class:0x2, length:0x90, resultlength:0x5E, handle:0
x530, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVers
ion\Explorer\FolderDescriptions\{A52BBA46-E9E1-435F-B3D9-28DAA648C0F6}"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"StreamResourceType", class:0x2, length:0x90, resultlength:0x5E, hand
le:0x530, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Current
Version\Explorer\FolderDescriptions\{A52BBA46-E9E1-435F-B3D9-28DAA648C0F6}"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"LocalRedirectOnly", class:0x2, length:0x90, resultlength:0x10, handle:0x530,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\E
xplorer\FolderDescriptions\{A52BBA46-E9E1-435F-B3D9-28DAA648C0F6}"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Roamable", class:0x2, length:0x90, resultlength:0x10, handle:0x530,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Ex
plorer\FolderDescriptions\{A52BBA46-E9E1-435F-B3D9-28DAA648C0F6}"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"PreCreate", class:0x2, length:0x90, resultlength:0x10, handle:0x530,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\E
xplorer\FolderDescriptions\{A52BBA46-E9E1-435F-B3D9-28DAA648C0F6}"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Stream", class:0x2, length:0x90, resultlength:0x10, handle:0x530, pa
th:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Expl
orer\FolderDescriptions\{A52BBA46-E9E1-435F-B3D9-28DAA648C0F6}"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
indows\CurrentVersion\Explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A113
0A75963}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
54
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Category", class:0x2, length:0x90, resultlength:0x10, handle:0x55C, path:"\R
EGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\F
olderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Name", class:0x2, length:0x90, resultlength:0x1C, handle:0x55C, path:"\REGIS
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Folde
rDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ParentFolder", class:0x2, length:0x90, resultlength:0x5A, handle:0x55C, path
:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explor
er\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Description", class:0x2, length:0x90, resultlength:0x5A, handle:0x55
C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion
\Explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"RelativePath", class:0x2, length:0x90, resultlength:0x40, handle:0x55C, path
:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explor
er\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"ParsingName", class:0x2, length:0x90, resultlength:0x40, handle:0x55
C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion
\Explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"InfoTip", class:0x2, length:0x90, resultlength:0x40, handle:0x55C, p
ath:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Exp
lorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"LocalizedName", class:0x2, length:0x90, resultlength:0x40, handle:0x
55C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersi
on\Explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Icon", class:0x2, length:0x90, resultlength:0x40, handle:0x55C, path
:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explor
er\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Security", class:0x2, length:0x90, resultlength:0x40, handle:0x55C,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Ex
plorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"StreamResource", class:0x2, length:0x90, resultlength:0x40, handle:0
x55C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVers
ion\Explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"StreamResourceType", class:0x2, length:0x90, resultlength:0x40, hand
le:0x55C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Current
Version\Explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"LocalRedirectOnly", class:0x2, length:0x90, resultlength:0x10, handle:0x55C,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\E
xplorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}"
pid:4092, tid:1488, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Roamable", class:0x2, length:0x90, resultlength:0x10, handle:0x55C,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Ex
plorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}"
0887-1001"
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtDeviceIoControlFile, status:
0x80000005, iostatus:0x80000005, information:0x8, code:0x6D0008, inlen:0x46, out
len:0x20, handle:0x530, path:"\??\MountPointManager"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, iostatus:0x0, information:0xFA, code:0x6D0008, inlen:0x46, outlen:0xFA, hand
le:0x530, path:"\??\MountPointManager"
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x558, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folder
s"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
30
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
54
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"History", class:0x2, length:0x90, resultlength:0x78, handle:0x558, path:"\RE
GISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Wi
ndows\CurrentVersion\Explorer\User Shell Folders"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x530, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\
Volume"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x53C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\
Volume\{3095dd51-a141-42a6-8c53-8590cc53fbc1}\"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
30
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
64
pid:4092, tid:1488, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
58
pid:4092, tid:2168, tick:0x33D700F, lvl:LOG, func:NtQueryValueKey, status:0x8000
0005, name:"Data", class:0x2, length:0x90, resultlength:0x566, handle:0x53C, pat
h:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Micros
oft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3095dd51-a141-42a68c53-8590cc53fbc1}"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Data", class:0x2, length:0x566, resultlength:0x566, handle:0x53C, path:"\REG
ISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Win
dows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3095dd51-a141-42a6-8c53-85
90cc53fbc1}"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtClose, status:0x0, handle:0x5
3C
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x53C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\
Volume"
pid:4092, tid:2168, tick:0x33D700F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x530, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\
Volume\{3095dd51-a141-42a6-8c53-8590cc53fbc1}\"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
3C
pid:4092, tid:1488, tick:0x33D701E, lvl:LOG, func:NtCreateFile, status:0xC000003
5, handle:0x0, access:0x100001, iostatus:0x331E528, information:0xA9206F, attrib
s:0x80, share:0x3, disposition:0x2, options:0x204021, path:"C:\Users\i92segoa"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Generation", class:0x2, length:0x90, resultlength:0x10, handle:0x530, path:"
\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft
\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3095dd51-a141-42a6-8c5
3-8590cc53fbc1}"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
30
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x530, c
lass:0x19, length:0x800, returnlength:0x14, sid:"S-1-16-8192", attributes:0x60
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
30
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:LdrResolveDelayLoadedAPI, stat
us:0x0, module:0x76B00000
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x530, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\
Volume"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x53C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\
Volume\{3095dd51-a141-42a6-8c53-8590cc53fbc1}\"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
30
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Generation", class:0x2, length:0x90, resultlength:0x10, handle:0x53C, path:"
\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft
\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3095dd51-a141-42a6-8c5
3-8590cc53fbc1}"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
3C
pid:4092, tid:1488, tick:0x33D701E, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x10, path:"C:\Users\i92segoa"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtDeviceIoControlFile, status:
0x0, iostatus:0x0, information:0x14, code:0x470807, inlen:0x24, outlen:0x14, han
dle:0xE4, path:"\Device\DeviceApi\CMApi"
pid:4092, tid:1488, tick:0x33D701E, lvl:LOG, func:NtCreateFile, status:0xC000003
5, handle:0x0, access:0x100001, iostatus:0x0, information:0xFFFFFFFF, attribs:0x
80, share:0x3, disposition:0x2, options:0x204021, path:"C:\Users\i92segoa\AppDat
a\Local"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtDeviceIoControlFile, status:
0x0, iostatus:0x0, information:0x652, code:0x470807, inlen:0x24, outlen:0x652, h
andle:0xE4, path:"\Device\DeviceApi\CMApi"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtDuplicateObject, status:0x0,
targethandle:0x53C, access:0x0, inherit:0x0, options:0x2, handle:0x51C
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtOpenFile, status:0x0, handle:0
x508, access:0x100080, iostatus:0x0, information:0x0, share:0x3, options:0x60, p
ath:"\??\STORAGE#Volume#{db216a5e-7a80-11e5-8d6c-806e6f6e6963}#0000000012D00000#
{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x53
0
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtQueryVolumeInformationFile, st
atus:0x0, iostatus:0x0, information:0x8, length:0x8, class:0x4, handle:0x508, pa
th:"\??\STORAGE#Volume#{db216a5e-7a80-11e5-8d6c-806e6f6e6963}#0000000012D00000#{
53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"
pid:4092, tid:1488, tick:0x33D701E, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x10, path:"C:\Users\i92segoa\AppData\Local"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x50
8
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtOpenFile, status:0x0, handle:0
x508, access:0x100080, iostatus:0x0, information:0x0, share:0x3, options:0x10, p
ath:"\??\STORAGE#Volume#{db216a5e-7a80-11e5-8d6c-806e6f6e6963}#0000000012D00000#
{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtDeviceIoControlFile, status:0x
0, iostatus:0x0, information:0x30, code:0x4D0008, inlen:0x0, outlen:0x208, handl
e:0x508, path:"\??\STORAGE#Volume#{db216a5e-7a80-11e5-8d6c-806e6f6e6963}#0000000
012D00000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x50
8
pid:4092, tid:1488, tick:0x33D701E, lvl:LOG, func:NtCreateFile, status:0xC000003
5, handle:0x0, access:0x100001, iostatus:0x0, information:0xFFFFFFFF, attribs:0x
80, share:0x3, disposition:0x2, options:0x204021, path:"C:\Users\i92segoa\AppDat
a\Local\Microsoft\Windows\History"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtCreateFile, status:0x0, handle
:0x508, access:0x100080, iostatus:0x0, information:0x0, attribs:0x80, share:0x3,
disposition:0x1, options:0x60, path:"\??\MountPointManager"
pid:4092, tid:556, tick:0x33D701E, lvl:LOG, func:NtDeviceIoControlFile, status:0
x80000005, iostatus:0x80000005, information:0x8, code:0x6D0008, inlen:0x46, outl
en:0x20, handle:0x508, path:"\??\MountPointManager"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtDeviceIoControlFile, status:0x
0, iostatus:0x0, information:0xC6, code:0x6D0008, inlen:0x46, outlen:0xC6, handl
e:0x508, path:"\??\MountPointManager"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x50
8
pid:4092, tid:1488, tick:0x33D701E, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x14, path:"C:\Users\i92segoa\AppData\Local\Microsoft\Windows\Histor
y"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:LdrUnloadDll, status:0x0, handle
:0x76B00000
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
51C
pid:4092, tid:1488, tick:0x33D701E, lvl:OK, func:NtSetInformationProcess, status
:0x0, class:0xC, length:0x4
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
53C
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handl
e:0x53C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246
3990887-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC
\Volume"
pid:4092, tid:1488, tick:0x33D701E, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x14, path:"C:\Users\i92segoa\AppData\Local\Microsoft\Windows\Histor
y"
pid:4092, tid:1488, tick:0x33D701E, lvl:OK, func:NtSetInformationProcess, status
:0x0, class:0xC, length:0x4
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handl
e:0x51C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246
3990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC
\Volume\{53fca6f1-4120-49f1-9dc9-20f142cb1ade}\"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
53C
pid:4092, tid:11200, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0x800
00005, name:"Data", class:0x2, length:0x90, resultlength:0x566, handle:0x51C, pa
th:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Micro
soft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{53fca6f1-4120-49f1
-9dc9-20f142cb1ade}"
pid:4092, tid:1488, tick:0x33D701E, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x2016, path:"C:\Users\i92segoa\AppData\Local\Microsoft\Windows\Hist
ory\History.IE5"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, n
ame:"Data", class:0x2, length:0x566, resultlength:0x566, handle:0x51C, path:"\RE
GISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Wi
ndows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{53fca6f1-4120-49f1-9dc9-2
0f142cb1ade}"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
51C
pid:4092, tid:1488, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x49C, access:0xF, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24639908
87-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Hi
story"
pid:4092, tid:1488, tick:0x33D701E, lvl:OK, func:NtSetValueKey, status:0x0, name
:"CachePrefix", index:0x0, type:0x1, size:0x12, handle:0x49C, path:"\REGISTRY\US
ER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Windows\Cur
rentVersion\Internet Settings\5.0\Cache\History"
pid:4092, tid:1488, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"CacheLimit", class:0x2, length:0x90, resultlength:0x10, handle:0x49C, path:"
\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft
\Windows\CurrentVersion\Internet Settings\5.0\Cache\History"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handl
e:0x51C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246
3990887-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC
\Volume"
pid:4092, tid:1488, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x4
9C
pid:4092, tid:1488, tick:0x33D701E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x49C, c
lass:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-2602383397-24
63990887-1001", attributes:0x0
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handl
e:0x53C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246
3990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC
\Volume\{53fca6f1-4120-49f1-9dc9-20f142cb1ade}\"
pid:4092, tid:1488, tick:0x33D701E, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x701C0000
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
51C
pid:4092, tid:1488, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x4
9C
pid:4092, tid:1488, tick:0x33D701E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x49C, c
lass:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-2602383397-24
63990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x92, handle:0x386, path:"\REGISTRY\USER\S-1-5-21
-2360094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, n
ame:"Generation", class:0x2, length:0x90, resultlength:0x10, handle:0x53C, path:
"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsof
t\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{53fca6f1-4120-49f1-9d
c9-20f142cb1ade}"
pid:4092, tid:1488, tick:0x33D701E, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x701C0000
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
53C
pid:4092, tid:1488, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x4
9C
pid:4092, tid:1488, tick:0x33D701E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtDuplicateObject, status:0x0,
targethandle:0x51C, access:0x0, inherit:0x0, options:0x2, handle:0x53C
pid:4092, tid:1488, tick:0x33D701E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
51C
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handl
e:0x51C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246
3990887-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC
\Volume"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handl
e:0x53C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246
3990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC
\Volume\{558339c2-fe4c-4d34-b973-1ff5b9ee3b95}\"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
51C
pid:4092, tid:11200, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0x800
00005, name:"Data", class:0x2, length:0x90, resultlength:0x566, handle:0x53C, pa
th:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Micro
soft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{558339c2-fe4c-4d34
-b973-1ff5b9ee3b95}"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, n
ame:"Data", class:0x2, length:0x566, resultlength:0x566, handle:0x53C, path:"\RE
GISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Wi
ndows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{558339c2-fe4c-4d34-b973-1
ff5b9ee3b95}"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
53C
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handl
e:0x53C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246
3990887-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC
\Volume"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handl
e:0x51C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246
3990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC
\Volume\{558339c2-fe4c-4d34-b973-1ff5b9ee3b95}\"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
53C
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, n
ame:"Generation", class:0x2, length:0x90, resultlength:0x10, handle:0x51C, path:
"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsof
t\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{558339c2-fe4c-4d34-b9
73-1ff5b9ee3b95}"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
51C
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtDuplicateObject, status:0x0,
targethandle:0x53C, access:0x0, inherit:0x0, options:0x2, handle:0x51C
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtOpenFile, status:0x0, handle:0
x508, access:0x100080, iostatus:0x0, information:0x0, share:0x3, options:0x60, p
ath:"\??\STORAGE#Volume#{db216a5e-7a80-11e5-8d6c-806e6f6e6963}#0000005D67000000#
{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x53
0
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtQueryVolumeInformationFile, st
atus:0x0, iostatus:0x0, information:0x8, length:0x8, class:0x4, handle:0x508, pa
th:"\??\STORAGE#Volume#{db216a5e-7a80-11e5-8d6c-806e6f6e6963}#0000005D67000000#{
53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x50
8
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtOpenFile, status:0x0, handle:0
x508, access:0x100080, iostatus:0x0, information:0x0, share:0x3, options:0x10, p
ath:"\??\STORAGE#Volume#{db216a5e-7a80-11e5-8d6c-806e6f6e6963}#0000005D67000000#
{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtDeviceIoControlFile, status:0x
0, iostatus:0x0, information:0x30, code:0x4D0008, inlen:0x0, outlen:0x208, handl
e:0x508, path:"\??\STORAGE#Volume#{db216a5e-7a80-11e5-8d6c-806e6f6e6963}#0000005
D67000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x50
8
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtCreateFile, status:0x0, handle
:0x508, access:0x100080, iostatus:0x0, information:0x0, attribs:0x80, share:0x3,
disposition:0x1, options:0x60, path:"\??\MountPointManager"
pid:4092, tid:556, tick:0x33D701E, lvl:LOG, func:NtDeviceIoControlFile, status:0
x80000005, iostatus:0x80000005, information:0x8, code:0x6D0008, inlen:0x46, outl
en:0x20, handle:0x508, path:"\??\MountPointManager"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtDeviceIoControlFile, status:0x
0, iostatus:0x0, information:0xFA, code:0x6D0008, inlen:0x46, outlen:0xFA, handl
e:0x508, path:"\??\MountPointManager"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x50
8
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:LdrUnloadDll, status:0x0, handle
:0x76B00000
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
51C
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
53C
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handl
e:0x53C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246
3990887-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC
\Volume"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handl
e:0x51C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246
3990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC
\Volume\{9391e3b4-adf4-4a69-b550-eac380a975b8}\"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
53C
pid:4092, tid:11200, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0x800
00005, name:"Data", class:0x2, length:0x90, resultlength:0x566, handle:0x51C, pa
th:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Micro
soft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{9391e3b4-adf4-4a69
-b550-eac380a975b8}"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, n
ame:"Data", class:0x2, length:0x566, resultlength:0x566, handle:0x51C, path:"\RE
GISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Wi
ndows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{9391e3b4-adf4-4a69-b550-e
ac380a975b8}"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
51C
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handl
e:0x51C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246
3990887-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC
\Volume"
pid:4092, tid:1488, tick:0x33D701E, lvl:WRN, func:New_NtQueryInformationToken::<
lambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0xC0000024, class:
0x1, length:0x40, returnlength:0xFFFFFFF8
pid:4092, tid:1488, tick:0x33D701E, lvl:WRN, func:New_NtQueryInformationToken::<
lambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0xC0000024, class:
0x1D, length:0x4, returnlength:0x0
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handl
e:0x53C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246
3990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC
\Volume\{9391e3b4-adf4-4a69-b550-eac380a975b8}\"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
51C
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
th:"\??\STORAGE#Volume#{db216a5d-7a80-11e5-8d6c-806e6f6e6963}#0000000001100000#{
53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001_Classes\Folder"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x50
8
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x558, access:0x20019, path:"\Registry\Machine\Software\Classes\Folder"
pid:4092, tid:1488, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x564, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows NT\Cu
rrentVersion\ProfileList"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x56, handle:0x55A, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\Folder"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x55A, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\Folder"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtOpenFile, status:0x0, handle:0
x508, access:0x100080, iostatus:0x0, information:0x0, share:0x3, options:0x10, p
ath:"\??\STORAGE#Volume#{db216a5d-7a80-11e5-8d6c-806e6f6e6963}#0000000001100000#
{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"
pid:4092, tid:1488, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Default", class:0x2, length:0x90, resultlength:0x44, handle:0x564, path:"\RE
GISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\ProfileList"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtDeviceIoControlFile, status:0x
0, iostatus:0x0, information:0x30, code:0x4D0008, inlen:0x0, outlen:0x208, handl
e:0x508, path:"\??\STORAGE#Volume#{db216a5d-7a80-11e5-8d6c-806e6f6e6963}#0000000
001100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"
pid:4092, tid:1488, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Default", class:0x2, length:0x90, resultlength:0x44, handle:0x564, path:"\RE
GISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\ProfileList"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_Classes\Folder\ShellEx\IconHandler"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x50
8
pid:4092, tid:1488, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
64
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\Folder\ShellE
x\IconHandler"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x92, handle:0x386, path:"\REGISTRY\USER\S-1-5-21
-2360094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x386, path:"\REGISTRY\USER\S-1-5-21-23
60094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtCreateFile, status:0x0, handle
:0x508, access:0x100080, iostatus:0x0, information:0x0, attribs:0x80, share:0x3,
disposition:0x1, options:0x60, path:"\??\MountPointManager"
pid:4092, tid:1488, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
04
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001_Classes\AllFilesystemObjects"
A1BD00000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x50
8
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_Classes\AllFilesystemObjects\DocObject"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtCreateFile, status:0x0, handle
:0x508, access:0x100080, iostatus:0x0, information:0x0, attribs:0x80, share:0x3,
disposition:0x1, options:0x60, path:"\??\MountPointManager"
pid:4092, tid:556, tick:0x33D701E, lvl:LOG, func:NtDeviceIoControlFile, status:0
x80000005, iostatus:0x80000005, information:0x8, code:0x6D0008, inlen:0x46, outl
en:0x20, handle:0x508, path:"\??\MountPointManager"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\AllFilesystem
Objects\DocObject"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtDeviceIoControlFile, status:0x
0, iostatus:0x0, information:0xC6, code:0x6D0008, inlen:0x46, outlen:0xC6, handl
e:0x508, path:"\??\MountPointManager"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x50
8
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0xA2, handle:0x53A, path:"\REGISTRY\USER\S-1-5-21
-2360094602-2602383397-2463990887-1001_CLASSES\Directory"
pid:4092, tid:556, tick:0x33D701E, lvl:OK, func:LdrUnloadDll, status:0x0, handle
:0x76B00000
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
51C
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x53A, path:"\REGISTRY\USER\S-1-5-21-23
60094602-2602383397-2463990887-1001_CLASSES\Directory"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
53C
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x504, access:0x2000000, path:"\Registry\Machine\Software\Classes\Directory"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"BrowseInPlace", class:0x2, length:0x90, resultlength:0x0, handle:0x5
3A, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001_CLASSES\
Directory"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"BrowseInPlace", class:0x2, length:0x90, resultlength:0x0, handle:0x5
06, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\Directory"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handl
e:0x53C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246
3990887-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC
\Volume"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
06
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0xA2, handle:0x53A, path:"\REGISTRY\USER\S-1-5-21
-2360094602-2602383397-2463990887-1001_CLASSES\Directory"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x53A, path:"\REGISTRY\USER\S-1-5-21-23
60094602-2602383397-2463990887-1001_CLASSES\Directory"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handl
e:0x51C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246
3990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC
\Volume\{cf83ff88-1dd4-4efd-a654-a8dcebea22af}\"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_CLASSES\Directory\BrowseInPlace"
GISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsoft\Wi
ndows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{7200359d-96f0-4a96-9857-6
e59f29ae985}"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
56
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
564
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0x56, handle:0x55A, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\Folder"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handl
e:0x564, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246
3990887-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC
\Volume"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x55A, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\Folder"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handl
e:0x560, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246
3990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC
\Volume\{7200359d-96f0-4a96-9857-6e59f29ae985}\"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
564
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, n
ame:"Generation", class:0x2, length:0x90, resultlength:0x10, handle:0x560, path:
"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE\Microsof
t\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{7200359d-96f0-4a96-98
57-6e59f29ae985}"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
560
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\Folder"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"NeverShowExt", class:0x2, length:0x90, resultlength:0xE, handle:0x55
A, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\Folder"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtCreateFile, status:0x0, hand
le:0x560, access:0x100080, iostatus:0x0, information:0x0, attribs:0x80, share:0x
3, disposition:0x1, options:0x60, path:"\??\MountPointManager"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0x72, handle:0x55E, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\AllFilesystemObjects"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtDeviceIoControlFile, status:
0x0, iostatus:0x0, information:0x6, code:0x6D0034, inlen:0x208, outlen:0x8, hand
le:0x560, path:"\??\MountPointManager"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x55E, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\AllFilesystemObjects"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
560
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtCreateFile, status:0x0, hand
le:0x560, access:0x100080, iostatus:0x0, information:0x0, attribs:0x80, share:0x
\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Winsock\Parameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtEnumerateValueKey, status:0x0
, index:0x0, class:0x1, length:0x186, resultlength:0x86, handle:0x578, path:"\RE
GISTRY\MACHINE\SOFTWARE\MICROSOFT\Windows\CurrentVersion\Explorer\SyncRootManage
r\Dropbox!S-1-5-21-2360094602-2602383397-2463990887-1001!personal\UserSyncRoots"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Transports", class:0x2, length:0x90, resultlength:0x42, handle:0x50C, path:"
\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Winsock\Parameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
78
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
0C
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20119, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Windows
\CurrentVersion\Explorer\SyncRootManager\Dropbox!S-1-5-21-2360094602-26023833972463990887-1001!personal\PendingRedirectionSyncRoots"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
74
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
38
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x50C, access:0x20019, path:"\REGISTRY\MACHINE\System\CurrentControlSet\Service
s\Psched\Parameters\Winsock"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
58
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0x8000
0005, name:"Mapping", class:0x2, length:0x90, resultlength:0xA4, handle:0x50C, p
ath:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Psched\Parameters\Winsock"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x717E0000
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0x8000
0005, name:"Mapping", class:0x2, length:0x90, resultlength:0xA4, handle:0x50C, p
ath:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Psched\Parameters\Winsock"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Mapping", class:0x2, length:0xA4, resultlength:0xA4, handle:0x50C, path:"\RE
GISTRY\MACHINE\SYSTEM\ControlSet001\Services\Psched\Parameters\Winsock"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
0C
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x558, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\Curre
ntVersion\Explorer\KindMap"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x50C, access:0x20019, path:"\REGISTRY\MACHINE\SYSTEM\CurrentControlSet\Service
s\Winsock\Setup Migration\Providers"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:".exe", class:0x2, length:0x90, resultlength:0x1C, handle:0x558, path:"\REGIS
TRY\MACHINE\SOFTWARE\MICROSOFT\Windows\CurrentVersion\Explorer\KindMap"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
58
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x504, access:0x20019, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Wi
nsock\Setup Migration\Providers\Psched"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x92, handle:0x386, path:"\REGISTRY\USER\S-1-5-21
-2360094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"WinSock 2.0 Provider ID", class:0x2, length:0x90, resultlength:0x1C, handle:
0x504, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Winsock\Setup Migra
tion\Providers\Psched"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
7-2463990887-1001_Classes\exefile"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
0C
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x538, access:0x20019, path:"\Registry\Machine\Software\Classes\exefile"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"C:\WINDOWS\System32\mswsock.dll", handle:0x73700000
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x58, handle:0x53A, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\exefile"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x73700000, name:"NSPStartup", ordinal:0x0, address:0x7370B
530, image:0x0, caller:0x775F615C
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x53A, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\exefile"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x73700000
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_Classes\exefile\CurVer"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\exefile\CurVe
r"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtCreateKey, status:0x0, handle
:0x504, access:0x20019, title:0x0, class:"Class", options:0x0, disposition:0x2,
path:"\REGISTRY\MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x58, handle:0x53A, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\exefile"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x53A, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\exefile"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x508, access:0x20019, path:"\REGISTRY\MACHINE\System\CurrentControlSet\Service
s\DnsCache\Parameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001_Classes\exefile"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies\Microsof
t\Windows NT\DnsClient"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x574, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\exefile\"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Hostname", class:0x2, length:0x90, resultlength:0x2C, handle:0x504, path:"\R
EGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
3A
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Hostname", class:0x2, length:0x90, resultlength:0x2C, handle:0x504, path:"\R
EGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters"
path:"\REGISTRY\MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x53A, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\exefile\shell\open"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x508, access:0x20019, path:"\REGISTRY\MACHINE\System\CurrentControlSet\Service
s\DnsCache\Parameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001_Classes\exefile\shell\open"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies\Microsof
t\Windows NT\DnsClient"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x560, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\exefile\shell\o
pen\"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\Software\Policies\Microsoft\Sy
stem\DNSClient"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x6E, handle:0x562, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\exefile\shell\open"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Domain", class:0x2, length:0x90, resultlength:0xE, handle:0x504, path:"\REGI
STRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x562, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\exefile\shell\open"
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Domain", class:0x2, length:0x90, resultlength:0xE, handle:0x504, path:"\REGI
STRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
04
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
08
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001_Classes\exefile\shell\open"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x564, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\exefile\shell\o
pen\"
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:DnsQueryEx, status:0x57
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
62
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:New_NtQueryInformationToken::<
lambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x53C,
class:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:11200, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x
53C
pid:4092, tid:8264, tick:0x33D701E, lvl:OK, func:NtCreateKey, status:0x0, handle
:0x508, access:0x20019, title:0x0, class:"Class", options:0x0, disposition:0x2,
path:"\REGISTRY\MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters"
lorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"EnableMultiHomedRouteConflicts", class:0x2, length:0x90, resultlengt
h:0x10, handle:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnsc
ache\Parameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"LocalizedName", class:0x2, length:0x90, resultlength:0x60, handle:0x57C, pat
h:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explo
rer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"RegistrationEnabled", class:0x2, length:0x90, resultlength:0x10, han
dle:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parame
ters"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Icon", class:0x2, length:0x90, resultlength:0x60, handle:0x57C, path
:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explor
er\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DisableDynamicUpdate", class:0x2, length:0x90, resultlength:0xE, han
dle:0x504, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameter
s"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Security", class:0x2, length:0x90, resultlength:0x60, handle:0x57C,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Ex
plorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"RegisterPrimaryName", class:0x2, length:0x90, resultlength:0x10, han
dle:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parame
ters"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"StreamResource", class:0x2, length:0x90, resultlength:0x60, handle:0
x57C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVers
ion\Explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"RegisterAdapterName", class:0x2, length:0x90, resultlength:0x10, han
dle:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parame
ters"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"StreamResourceType", class:0x2, length:0x90, resultlength:0x60, hand
le:0x57C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Current
Version\Explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"EnableAdapterDomainNameRegistration", class:0x2, length:0x90, result
length:0xE, handle:0x504, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\
Tcpip\Parameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"LocalRedirectOnly", class:0x2, length:0x90, resultlength:0x60, handl
e:0x57C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentV
ersion\Explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"RegisterReverseLookup", class:0x2, length:0x90, resultlength:0x10, h
andle:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Para
meters"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Roamable", class:0x2, length:0x90, resultlength:0x60, handle:0x57C,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Ex
plorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DisableReverseAddressRegistrations", class:0x2, length:0x90, resultl
ength:0xE, handle:0x504, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\T
cpip\Parameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"PreCreate", class:0x2, length:0x90, resultlength:0x10, handle:0x57C, path:"\
REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\
FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"RegisterWanAdapters", class:0x2, length:0x90, resultlength:0x10, han
dle:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parame
ters"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Stream", class:0x2, length:0x90, resultlength:0x10, handle:0x57C, pa
th:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Expl
orer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DisableWanDynamicUpdate", class:0x2, length:0x90, resultlength:0xE,
handle:0x504, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parame
ters"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"PublishExpandedPath", class:0x2, length:0x90, resultlength:0x10, han
dle:0x57C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Curren
tVersion\Explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"RegistrationTtl", class:0x2, length:0x90, resultlength:0x10, handle:
0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters
"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DefinitionFlags", class:0x2, length:0x90, resultlength:0x10, handle:
0x57C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVer
sion\Explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DefaultRegistrationTTL", class:0x2, length:0x90, resultlength:0xE, h
andle:0x504, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Paramet
ers"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Attributes", class:0x2, length:0x90, resultlength:0x10, handle:0x57C, path:"
\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer
\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"RegistrationRefreshInterval", class:0x2, length:0x90, resultlength:0
x10, handle:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscach
e\Parameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"FolderTypeID", class:0x2, length:0x90, resultlength:0x10, handle:0x5
7C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersio
n\Explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DefaultRegistrationRefreshInterval", class:0x2, length:0x90, resultl
ength:0xE, handle:0x504, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\T
cpip\Parameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"InitFolderHandler", class:0x2, length:0x90, resultlength:0x10, handl
e:0x57C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentV
ersion\Explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"RegistrationMaxAddressCount", class:0x2, length:0x90, resultlength:0
x10, handle:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscach
e\Parameters"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"MaxNumberOfAddressesToRegister", class:0x2, length:0x90, resultlengt
h:0xE, handle:0x504, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip
\Parameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Micro
soft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C
-E74B8BE3B067}\PropertyBag"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
7C
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"UpdateSecurityLevel", class:0x2, length:0x90, resultlength:0x10, han
dle:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parame
ters"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"UpdateSecurityLevel", class:0x2, length:0x90, resultlength:0x10, han
dle:0x504, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameter
s"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"UpdateTopLevelDomainZones", class:0x2, length:0x90, resultlength:0x1
0, handle:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\
Parameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x57C, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24639908
87-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DowncaseSpnCauseApiOwnerIsTooLazy", class:0x2, length:0x90, resultle
ngth:0x10, handle:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\D
nscache\Parameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\K
nownFolders"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"RegistrationOverwrite", class:0x2, length:0x90, resultlength:0x10, h
andle:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Para
meters"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
7C
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"MaxCacheSize", class:0x2, length:0x90, resultlength:0x10, handle:0x5
08, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"MaxCacheTtl", class:0x2, length:0x90, resultlength:0x10, handle:0x50
8, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x57C, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\Curre
ntVersion\Explorer\User Shell Folders"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"MaxNegativeCacheTtl", class:0x2, length:0x90, resultlength:0x10, han
dle:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parame
ters"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"AdapterTimeoutLimit", class:0x2, length:0x90, resultlength:0x10, han
dle:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parame
ters"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Common Start Menu", class:0x2, length:0x90, resultlength:0x62, handle:0x57C,
path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\E
xplorer\User Shell Folders"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"ServerPriorityTimeLimit", class:0x2, length:0x90, resultlength:0x10,
handle:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Pa
rameters"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"MaxCachedSockets", class:0x2, length:0x90, resultlength:0x10, handle
:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameter
s"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
84
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DisableServerUnreachability", class:0x2, length:0x90, resultlength:0
x10, handle:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscach
e\Parameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
7C
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"EnableMulticast", class:0x2, length:0x90, resultlength:0x10, handle:
0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters
"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x57C, c
lass:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"MulticastResponderFlags", class:0x2, length:0x90, resultlength:0x10,
handle:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Pa
rameters"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"MulticastSenderFlags", class:0x2, length:0x90, resultlength:0x10, ha
ndle:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Param
eters"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x584, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Windows\Curre
ntVersion\Explorer\FolderDescriptions"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"MulticastSenderMaxTimeout", class:0x2, length:0x90, resultlength:0x1
0, handle:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\
Parameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x560, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\W
indows\CurrentVersion\Explorer\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092
E34987A}"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtClose, status:0x0, handle:0x5
84
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DnsTest", class:0x2, length:0x90, resultlength:0x10, handle:0x508, p
ath:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Category", class:0x2, length:0x90, resultlength:0x10, handle:0x560, path:"\R
EGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\F
olderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"UseCompartments", class:0x2, length:0x90, resultlength:0x10, handle:
0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters
"
pid:4092, tid:2168, tick:0x33D701E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Name", class:0x2, length:0x90, resultlength:0x1A, handle:0x560, path:"\REGIS
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Folde
rDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}"
pid:4092, tid:8264, tick:0x33D701E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"CacheAllCompartments", class:0x2, length:0x90, resultlength:0x10, ha
ndle:0x508, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Param
eters"
FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Stream", class:0x2, length:0x90, resultlength:0x10, handle:0x588, pa
th:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Expl
orer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}"
pid:4092, tid:1488, tick:0x33D702E, lvl:OK, func:NtDuplicateObject, status:0x0,
targethandle:0x4E0, access:0x0, inherit:0x0, options:0x2, handle:0xFFFFFFFE
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"PublishExpandedPath", class:0x2, length:0x90, resultlength:0x10, han
dle:0x588, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Curren
tVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DefinitionFlags", class:0x2, length:0x90, resultlength:0x10, handle:
0x588, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVer
sion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}"
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtCreateFile, status:0x0, handl
e:0x55C, access:0xC0140000, iostatus:0x0, information:0x0, attribs:0x0, share:0x
3, disposition:0x3, options:0x0, path:"\Device\Afd\Endpoint"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Attributes", class:0x2, length:0x90, resultlength:0x10, handle:0x588, path:"
\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer
\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}"
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x514, iostatus:0x0, information:0x0, code:0x12047, inlen:0xA4, outlen
:0x10, handle:0x55C, path:"\Device\Afd\Endpoint"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"FolderTypeID", class:0x2, length:0x90, resultlength:0x10, handle:0x5
88, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersio
n\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}"
pid:4092, tid:1488, tick:0x33D702E, lvl:OK, func:NtCreateFile, status:0x0, handl
e:0x53C, access:0xC0140000, iostatus:0x0, information:0x0, attribs:0x0, share:0x
3, disposition:0x3, options:0x0, path:"\Device\Afd\Endpoint"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"InitFolderHandler", class:0x2, length:0x90, resultlength:0x10, handl
e:0x588, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentV
ersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}"
pid:4092, tid:1488, tick:0x33D702E, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, event:0x50C, iostatus:0x0, information:0x0, code:0x12047, inlen:0xA4, outlen
:0x10, handle:0x53C, path:"\Device\Afd\Endpoint"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x530, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\W
indows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C854
80369C7}\PropertyBag"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
88
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x588, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24639908
87-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\K
nownFolders"
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x20, path:"C:\WINDOWS\System32\mswsock.dll"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
88
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
orer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"PublishExpandedPath", class:0x2, length:0x90, resultlength:0x5A, han
dle:0x588, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\Curren
tVersion\Explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}"
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x20, path:"C:\WINDOWS\System32\mswsock.dll"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DefinitionFlags", class:0x2, length:0x90, resultlength:0x5A, handle:
0x588, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVer
sion\Explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}"
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2CCD898, class:0x3, length:0x14
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:LdrUnloadDll, status:0x0, handl
e:0x73700000
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"Attributes", class:0x2, length:0x90, resultlength:0x5A, handle:0x588
, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\
Explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"FolderTypeID", class:0x2, length:0x90, resultlength:0x5A, handle:0x5
88, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersio
n\Explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"InitFolderHandler", class:0x2, length:0x90, resultlength:0x5A, handl
e:0x588, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentV
ersion\Explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x58C, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\W
indows\CurrentVersion\Explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F39
10AB8FE}\PropertyBag"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
88
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
94
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x20, path:"C:\WINDOWS\System32\wshqos.dll"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKey, status:0xC0000034,
handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{0000
0323-0000-0000-C000-000000000046}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x594, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Rpc\Extensions"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"NdrOleExtDLL", class:0x2, length:0x21A, resultlength:0x24, handle:0x594, pat
h:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Rpc\Extensions"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
94
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"combase.dll", module:0x74DC0000
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74DC0000, name:"NdrOleInitializeExtension", ordinal:0x0,
address:0x74E96DA0, image:0x0, caller:0x770340A5
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtCreateFile, status:0x0, handl
e:0x580, access:0x80100080, iostatus:0x0, information:0x1, attribs:0x0, share:0x
5, disposition:0x1, options:0x60, path:"C:\WINDOWS\System32\wshqos.dll"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74DC0000, name:"CoGetMarshalSizeMax", ordinal:0x0, addres
s:0x74E45230, image:0x0, caller:0x74E96DFA
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74DC0000, name:"CoMarshalInterface", ordinal:0x0, address
7-2463990887-1001_CLASSES\Local Settings\Software\Microsoft\Ole\FeatureDevelopme
ntProperties"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
90
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20119, path:"\REGISTRY\MACHINE\Software\Microsoft\Ole\Fea
tureDevelopmentProperties"
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x20, path:"C:\WINDOWS\System32\wshqos.dll"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x74DC0000
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x590, access:0x20119, path:"\Registry\Machine\SOFTWARE\Policies\Microsoft\Window
s\Appx"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"AllowDevelopmentWithoutDevLicense", class:0x2, length:0x18, resultlength:0x1
0, handle:0x590, path:"\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\App
x"
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtCreateFile, status:0x0, handl
e:0x580, access:0x80100080, iostatus:0x0, information:0x1, attribs:0x0, share:0x
5, disposition:0x1, options:0x60, path:"C:\WINDOWS\System32\wshqos.dll"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
90
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtCreateSection, status:0x0, ha
ndle:0x584, access:0x5, pageattribs:0x2, sectionattribs:0x11000000, file:0x580
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x590, access:0x20119, path:"\Registry\Machine\SOFTWARE\Microsoft\Windows\Current
Version\AppModelUnlock"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"AllowDevelopmentWithoutDevLicense", class:0x2, length:0x18, resultle
ngth:0x0, handle:0x590, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Windows\Curre
ntVersion\AppModelUnlock"
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtMapViewOfSection, status:0x40
000003, address:0x5A0000, zerobits:0x0, commitsize:0x0, viewsize:0x8000, disposi
tion:0x1, type:0x800000, protect:0x2, handle:0x584, path:"C:\WINDOWS\System32\ws
hqos.dll"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
90
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
84
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
80
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"ntdll.dll", module:0x77C10000
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2D799A0, class:0x3, length:0x14
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x77C10000, name:"NtQuerySystemInformation", ordinal:0x0, a
ddress:0x77C86F30, image:0x0, caller:0x74EA12A1
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5A0000
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x20, path:"C:\WINDOWS\System32\wshqos.dll"
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtCreateFile, status:0x0, handl
e:0x580, access:0x80100080, iostatus:0x0, information:0x1, attribs:0x0, share:0x
5, disposition:0x1, options:0x60, path:"C:\WINDOWS\System32\wshqos.dll"
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtCreateSection, status:0x0, ha
ndle:0x584, access:0x5, pageattribs:0x2, sectionattribs:0x11000000, file:0x580
pid:4092, tid:8264, tick:0x33D702E, lvl:OK, func:NtMapViewOfSection, status:0x40
000003, address:0x5A0000, zerobits:0x0, commitsize:0x0, viewsize:0x8000, disposi
88
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
98
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1D, length:0x4, returnlength:0x4
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQuerySecurityObject, status:
0xC0000023, class:0x17, length:0x0, requiredlength:0xE8, handle:0x598, path:"\RP
C Control"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQuerySecurityObject, status:0
x0, class:0x17, length:0xE8, requiredlength:0xE8, handle:0x598, path:"\RPC Contr
ol"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x588, c
lass:0xA, length:0x38, returnlength:0x38
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x588, c
lass:0x4, length:0x48, returnlength:0x20
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x588, c
lass:0x19, length:0x4C, returnlength:0x14, sid:"S-1-16-8192", attributes:0x60
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:New_NtQueryInformationToken::<
lambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0xC0000023, token:
0x588, class:0x5, length:0x0, returnlength:0x20
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x588, c
lass:0x5, length:0x20, returnlength:0x20
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:New_NtQueryInformationToken::<
lambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0xC0000023, token:
0x588, class:0x6, length:0x0, returnlength:0x60
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x588, c
lass:0x6, length:0x60, returnlength:0x60
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FC, class:0x29, length:0x48, returnlength:0x4
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x588, c
lass:0x29, length:0x48, returnlength:0x4
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x588, c
lass:0xA, length:0x38, returnlength:0x38
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x588, c
lass:0x4, length:0x48, returnlength:0x20
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x588, c
lass:0x19, length:0x4C, returnlength:0x14, sid:"S-1-16-8192", attributes:0x60
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:New_NtQueryInformationToken::<
lambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0xC0000023, token:
0x588, class:0x5, length:0x0, returnlength:0x20
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x588, c
lass:0x5, length:0x20, returnlength:0x20
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:New_NtQueryInformationToken::<
lambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0xC0000023, token:
0x588, class:0x6, length:0x0, returnlength:0x60
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x588, c
lass:0x6, length:0x60, returnlength:0x60
60094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001_Classes\ExplorerCLSIDFlags\{66742402-F9B9-11D1-A202-0000F81FED
EE}"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\Registry\Machine\Software\Classes\ExplorerC
LSIDFlags\{66742402-F9B9-11D1-A202-0000F81FEDEE}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0xBA, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{66742402-F9B9-11D1-A202-0000F81FEDEE}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{66742402-F9B9-11D1-A202-0000F81FEDEE}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\WOW6432Node\CLSID\{66742402-F9B9-11D1-A202-0000F81FE
DEE}"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"UseInProcHandlerCache", class:0x2, length:0x90, resultlength:0x80000
000, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{6
6742402-F9B9-11D1-A202-0000F81FEDEE}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0xBA, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{66742402-F9B9-11D1-A202-0000F81FEDEE}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{66742402-F9B9-11D1-A202-0000F81FEDEE}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\WOW6432Node\CLSID\{66742402-F9B9-11D1-A202-0000F81FE
DEE}"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"UseOutOfProcHandlerCache", class:0x2, length:0x90, resultlength:0x80
000000, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID
\{66742402-F9B9-11D1-A202-0000F81FEDEE}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
9E
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x59C, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{76765B11-3
F95-4AF2-AC9D-EA55D8994F1A}"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"AppID", class:0x2, length:0x400, resultlength:0x66742402, handle:0x5
9C, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{76765B11-3F95-4A
F2-AC9D-EA55D8994F1A}"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKey, status:0xC0000034,
handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node
\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}\LocalServer32"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
9C
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x92, handle:0x3C2, path:"\Registry\User\S-1-5-21
-2360094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x3C2, path:"\Registry\User\S-1-5-21-23
60094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\Registry\User\S-1-5-21-2360094602-260238339
7-2463990887-1001_Classes\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x59C, access:0x20019, path:"\Registry\Machine\Software\Classes\CLSID\{76765B11
-3F95-4AF2-AC9D-EA55D8994F1A}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0xBA, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_Classes\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}\T
reatAs"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\C
LSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}\TreatAs"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x204, resultlength:0xBA, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0xBA, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994
F1A}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"", class:0x2, length:0x90, resultlength:0x52, handle:0x59E, path:"\REGISTRY\
MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A
}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0xBA, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994
F1A}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"", class:0x2, length:0x90, resultlength:0x52, handle:0x59E, path:"\REGISTRY\
MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A
}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0xBA, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001_Classes\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1
A}\InprocServer32"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x5A0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLS
ID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}\InprocServer32"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0xD8, handle:0x5A2, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}\InProcServe
r32"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x5A2, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}\InProcServer32
"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994
F1A}\InProcServer32"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"InprocServer32", class:0x2, length:0x90, resultlength:0x0, handle:0x
5A2, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{76765B11-3F95-4
AF2-AC9D-EA55D8994F1A}\InProcServer32"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0xD8, handle:0x5A2, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}\InProcServe
r32"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x5A2, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}\InProcServer32
"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994
F1A}\InProcServer32"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryValueKey, status:0x0, na
FC4}\InprocServer32"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"InprocServer32", class:0x2, length:0x90, resultlength:0x0, handle:0x
5A2, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{7B8A2D94-0AC9-1
1D1-896C-00C04FB6BFC4}\InprocServer32"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0xD8, handle:0x5A2, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}\InprocServe
r32"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x5A2, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}\InprocServer32
"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\WOW6432Node\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6B
FC4}\InprocServer32"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"", class:0x2, length:0x90, resultlength:0x4A, handle:0x5A2, path:"\REGISTRY\
MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4
}\InprocServer32"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0xD8, handle:0x5A2, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}\InprocServe
r32"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x5A2, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}\InprocServer32
"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\WOW6432Node\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6B
FC4}\InprocServer32"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"", class:0x2, length:0x90, resultlength:0x4A, handle:0x5A2, path:"\REGISTRY\
MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4
}\InprocServer32"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0xD8, handle:0x5A2, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}\InprocServe
r32"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x5A2, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}\InprocServer32
"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\WOW6432Node\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6B
FC4}\InprocServer32"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ThreadingModel", class:0x2, length:0x90, resultlength:0x16, handle:0x5A2, pa
th:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{7B8A2D94-0AC9-11D1-896
C-00C04FB6BFC4}\InprocServer32"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
A2
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0xBA, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_Classes\WOW6432Node\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}\I
nprocHandler32"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\C
LSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}\InprocHandler32"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0xBA, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_Classes\WOW6432Node\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}\I
nprocHandler"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\C
LSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}\InprocHandler"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
9E
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x92, handle:0x422, path:"\Registry\User\S-1-5-21
-2360094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x422, path:"\Registry\User\S-1-5-21-23
60094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\Registry\User\S-1-5-21-2360094602-260238339
7-2463990887-1001_Classes\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x59C, access:0x20019, path:"\Registry\Machine\Software\Classes\CLSID\{7B8A2D94
-0AC9-11D1-896C-00C04FB6BFC4}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0xBA, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001_Classes\WOW6432Node\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC
4}\TreatAs"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432No
de\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}\TreatAs"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
9E
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"C:\Windows\SysWOW64\urlmon.dll", handle:0x73500000
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x73500000, name:"DllGetClassObject", ordinal:0x0, address:
0x73578D60, image:0x0, caller:0x74E6C7CB
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:LdrGetProcedureAddressForCalle
r, status:0xC0000139, module:0x73500000, name:"DllGetActivationFactory", ordinal
:0x0, image:0x0, caller:0x74E6C7DD
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x73500000, name:"DllCanUnloadNow", ordinal:0x0, address:0x
73579820, image:0x0, caller:0x74E6C841
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:CoCreateInstance, hr:0x0, clsid
:7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4, context:0x1, riid:79EAC9EE-BAF9-11CE-8C82
-00AA004BA90B
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_I
NITIALIZE_URLACTION_SHELLEXECUTE_TO_ALLOW_KB936610"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft
\Internet Explorer\Main\FeatureControl\FEATURE_INITIALIZE_URLACTION_SHELLEXECUTE
_TO_ALLOW_KB936610"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x59C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Internet Explorer\Security"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DisableSecuritySettingsCheck", class:0x2, length:0x90, resultlength:
0x0, handle:0x59C, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-246399088
7-1001\SOFTWARE\Microsoft\Internet Explorer\Security"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
9C
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x59C, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Internet Expl
orer\Security"
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DisableSecuritySettingsCheck", class:0x2, length:0x90, resultlength:
0x0, handle:0x59C, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Intern
et Explorer\Security"
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:NtClose, status:0x0, handle:0x5
9C
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"API-MS-WIN-CORE-URL-L1-1-0.DLL", handle:0x776F0000
pid:4092, tid:2168, tick:0x33D702E, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x776F0000, name:"PathCreateFromUrlW", ordinal:0x0, address
:0x77797370, image:0x0, caller:0x72A3C190
pid:4092, tid:2168, tick:0x33D702E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
ARE\Classes\exefile\shell\open\command"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x5A2, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\exefile\shell\open\command"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\exefile\shell\open\command"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"", class:0x2, length:0x90, resultlength:0x1C, handle:0x5A2, path:"\REGISTRY\
MACHINE\SOFTWARE\Classes\exefile\shell\open\command"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtClose, status:0x0, handle:0x5
A2
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x5A0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{CDC82860-4
68D-4D4E-B7E7-C298FF23AB2C}"
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"AppID", class:0x2, length:0x400, resultlength:0x1D0000, handle:0x5A0
, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E
-B7E7-C298FF23AB2C}"
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:NtOpenKey, status:0xC0000034,
handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node
\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2C}\LocalServer32"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtClose, status:0x0, handle:0x5
A0
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x92, handle:0x3C2, path:"\Registry\User\S-1-5-21
-2360094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x3C2, path:"\Registry\User\S-1-5-21-23
60094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\Registry\User\S-1-5-21-2360094602-260238339
7-2463990887-1001_Classes\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2C}"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x5A0, access:0x20019, path:"\Registry\Machine\Software\Classes\CLSID\{CDC82860
-468D-4D4E-B7E7-C298FF23AB2C}"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0xBA, handle:0x5A2, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2C}"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x5A2, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2C}"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2C}\T
reatAs"
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\C
LSID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2C}\TreatAs"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x204, resultlength:0xBA, handle:0x5A2, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2C}"
"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23A
B2C}\InProcServer32"
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"InprocServer32", class:0x2, length:0x90, resultlength:0x0, handle:0x
59E, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{CDC82860-468D-4
D4E-B7E7-C298FF23AB2C}\InProcServer32"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0xD8, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2C}\InProcServe
r32"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2C}\InProcServer32
"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23A
B2C}\InProcServer32"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"", class:0x2, length:0x90, resultlength:0x60, handle:0x59E, path:"\REGISTRY\
MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2C
}\InProcServer32"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0xD8, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2C}\InProcServe
r32"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2C}\InProcServer32
"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23A
B2C}\InProcServer32"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"", class:0x2, length:0x90, resultlength:0x60, handle:0x59E, path:"\REGISTRY\
MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2C
}\InProcServer32"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0xD8, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2C}\InProcServe
r32"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2C}\InProcServer32
"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23A
B2C}\InProcServer32"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"", class:0x2, length:0x90, resultlength:0x60, handle:0x59E, path:"\REGISTRY\
MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2C
}\InProcServer32"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0xD8, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2C}\InProcServe
r32"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x59E, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2C}\InProcServer32
"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23A
B2C}\InProcServer32"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ThreadingModel", class:0x2, length:0x90, resultlength:0x16, handle:0x59E, pa
th:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E
7-C298FF23AB2C}\InProcServer32"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtClose, status:0x0, handle:0x5
9E
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0xBA, handle:0x5A2, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2C}"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x5A2, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2C}"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2C}\I
nprocHandler32"
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\C
LSID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2C}\InprocHandler32"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0xBA, handle:0x5A2, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2C}"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x5A2, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2C}"
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
0, address:0x5A0000
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5A0000, zerobits:0x0, commitsize:0x0, offset:0x210000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x3760000
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding directory _CrashReporter@1.0.0.0 with flags: 2."
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding directory _Firefox@1.0.0.0 with flags: 2."
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding directory _MaintenanceService@1.0.0.0 with flags: 2."
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding directory _Mozilla.WebAppRT@1.0.0.0 with flags: 2."
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding directory _Nullsoft.NSIS.exehead@1.0.0.0 with flags: 2."
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding directory _plugin-container@1.0.0.0 with flags: 2."
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding directory _plugin-hang-ui@1.0.0.0 with flags: 2."
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding directory _Updater@1.0.0.0 with flags: 2."
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding directory Manifests with flags: 2."
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding directory X86_7zS.sfx.exe@1.0.0.0 with flags: 2."
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x3760000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x10
000, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5A0000
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:RecurseDirectoryConfig, log:"D
uplicate directory Manifests will not be added as it is at lower layer."
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding directory x86_Adobe.FlashPlayer.Installer@14.0.0.125 with flags: 2."
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding directory x86_Adobe.FlashPlayer.Uninstaller@14.0.0.125 with flags: 2."
pid:4092, tid:2168, tick:0x33D703E, lvl:LOG, func:RecurseDirectoryConfig, log:"A
dding directory X86_Adobe.SAFlashPlayer@14.0.0.125 with flags: 2."
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5A0000, zerobits:0x0, commitsize:0x0, offset:0x210000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x3760000
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x3760000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x10
000, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5A0000
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x5A0000, zerobits:0x0, commitsize:0x0, offset:0x210000, viewsize:0x100
00, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x3760000
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x3760000, zerobits:0x0, commitsize:0x0, offset:0x260000, viewsize:0x10
000, disposition:0x2, type:0x0, protect:0x2, handle:0x78
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtUnmapViewOfSection, status:0x
0, address:0x5A0000
pid:4092, tid:2168, tick:0x33D703E, lvl:OK, func:NtMapViewOfSection, status:0x0,
D4
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:SetLastSeenChildProcThread, lo
g:"Setting last seen child proc thread to 0x5C8."
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtClose, status:0x0, handle:0x5
B0
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtClose, status:0x0, handle:0x5
AC
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:CreateProcessInternalW, ret:0x1
, gle:0x0, name:"C:\Program Files (x86)\Mozilla Firefox\firefox.exe", commandlin
e:"\"C:\Program Files (x86)\Mozilla Firefox\firefox.exe\" ", inherit:0x0, flags:
0x4080404, currentdir:"C:\Users\i92segoa\Desktop\Firefox SEO\"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x92, handle:0x386, path:"\REGISTRY\USER\S-1-5-21
-2360094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x386, path:"\REGISTRY\USER\S-1-5-21-23
60094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001_Classes\Applications\firefox.exe"
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\Registry\Machine\Software\Classes\Applicati
ons\firefox.exe"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:LdrResolveDelayLoadedAPI, statu
s:0x0, module:0x76B00000
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtOpenSection, status:0xC00000
34, handle:0x0, access:0xF, path:"\KnownDlls32\pcacli.dll"
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtQueryAttributesFile, status:
0xC0000034, path:"C:\Users\i92segoa\Desktop\Firefox SEO\pcacli.dll"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x20, path:"C:\WINDOWS\SYSTEM32\pcacli.dll"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtOpenFile, status:0x0, handle:
0x5AC, access:0x100021, iostatus:0x0, information:0x1, share:0x5, options:0x60,
path:"C:\WINDOWS\SYSTEM32\pcacli.dll"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtCreateSection, status:0x0, ha
ndle:0x5B0, access:0xF, pageattribs:0x10, sectionattribs:0x1000000, file:0x5AC
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x60AE0000, zerobits:0x0, commitsize:0x0, viewsize:0xC000, disposition:
0x1, type:0x800000, protect:0x4, handle:0x5B0, path:"C:\WINDOWS\SYSTEM32\pcacli.
dll"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtClose, status:0x0, handle:0x5
B0
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtClose, status:0x0, handle:0x5
AC
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtOpenKey, status:0x0, handle:0
x5B0, access:0x1, path:"\Registry\Machine\Software\Microsoft\Windows NT\CurrentV
ersion\AppCompatFlags"
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"LogFlags", class:0x2, length:0x14, resultlength:0x0, handle:0x5B0, p
ath:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\
AppCompatFlags"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtClose, status:0x0, handle:0x5
B0
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x20, path:"C:\WINDOWS\SYSTEM32\kernelbase.dll"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:LdrGetDllHandle, status:0x0, na
me:"api-ms-win-eventing-provider-l1-1-0", module:0x776F0000
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x776F0000, name:"EventSetInformation", ordinal:0x0, addres
s:0x77C39FC0, image:0x0, caller:0x60AE409A
ARE\Classes\exefile\shell\open"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x53A, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\exefile\shell\open"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_Classes\exefile\shell\open\command"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x5E4, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\exefile\shell\open\
command"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0x7E, handle:0x5E6, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\exefile\shell\open\command"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x5E6, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\exefile\shell\open\command"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\exefile\shell\open\command"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"", class:0x2, length:0x90, resultlength:0x1C, handle:0x5E6, path:"\REGISTRY\
MACHINE\SOFTWARE\Classes\exefile\shell\open\command"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtClose, status:0x0, handle:0x5
E6
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x92, handle:0x386, path:"\REGISTRY\USER\S-1-5-21
-2360094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x386, path:"\REGISTRY\USER\S-1-5-21-23
60094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-260238339
7-2463990887-1001_Classes\Applications\%1.exe"
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\Registry\Machine\Software\Classes\Applicati
ons\%1.exe"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0x6E, handle:0x53A, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\exefile\shell\open"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x53A, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\exefile\shell\open"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_Classes\exefile\shell\open\command"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x5E4, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\exefile\shell\open\
command"
60094602-2602383397-2463990887-1001_Classes"
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\Registry\User\S-1-5-21-2360094602-260238339
7-2463990887-1001_Classes\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x564, access:0x20019, path:"\Registry\Machine\Software\Classes\CLSID\{9AC9FBE1
-E0A2-4AD6-B4EE-E212013EA917}"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x180, resultlength:0xBA, handle:0x566, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x566, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001_Classes\WOW6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}\T
reatAs"
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x1, path:"\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\C
LSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}\TreatAs"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x204, resultlength:0xBA, handle:0x566, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0xBA, handle:0x566, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x566, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\WOW6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA
917}"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"", class:0x2, length:0x90, resultlength:0x4E, handle:0x566, path:"\REGISTRY\
MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917
}"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x3, length:0x188, resultlength:0xBA, handle:0x566, path:"\REGISTRY\MACHINE\SOFTW
ARE\Classes\WOW6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryKey, status:0x0, class:0
x7, length:0x4, resultlength:0x4, handle:0x566, path:"\REGISTRY\MACHINE\SOFTWARE
\Classes\WOW6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0xFFFFFF
FA, class:0x1, length:0x50, returnlength:0x24, sid:"S-1-5-21-2360094602-26023833
97-2463990887-1001", attributes:0x0
pid:4092, tid:2168, tick:0x33D70DA, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383
397-2463990887-1001_Classes\WOW6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA
917}"
pid:4092, tid:2168, tick:0x33D70DA, lvl:OK, func:NtQueryValueKey, status:0x0, na
ISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\Cry
ptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.2"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtClose, status:0x0, handle:0x5
C8
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x5, class:0x0, length:0x120, resultlength:0x42, handle:0x564, path:"\REGISTR
Y\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDl
lDecodeObjectEx"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x5C8, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\C
ryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.3"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtQueryKey, status:0x0, class:0
x4, length:0xB0, resultlength:0x28, handle:0x5C8, path:"\REGISTRY\MACHINE\SOFTWA
RE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\
1.2.840.113549.1.9.16.2.3"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtEnumerateValueKey, status:0x0
, index:0x0, class:0x1, length:0xDC, resultlength:0x62, handle:0x5C8, path:"\REG
ISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\Cry
ptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.3"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtEnumerateValueKey, status:0x0
, index:0x1, class:0x1, length:0xDC, resultlength:0x52, handle:0x5C8, path:"\REG
ISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\Cry
ptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.3"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtClose, status:0x0, handle:0x5
C8
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x6, class:0x0, length:0x120, resultlength:0x42, handle:0x564, path:"\REGISTR
Y\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDl
lDecodeObjectEx"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x5C8, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\C
ryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.4"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtQueryKey, status:0x0, class:0
x4, length:0xB0, resultlength:0x28, handle:0x5C8, path:"\REGISTRY\MACHINE\SOFTWA
RE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\
1.2.840.113549.1.9.16.2.4"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtEnumerateValueKey, status:0x0
, index:0x0, class:0x1, length:0xDC, resultlength:0x62, handle:0x5C8, path:"\REG
ISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\Cry
ptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.4"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtEnumerateValueKey, status:0x0
, index:0x1, class:0x1, length:0xDC, resultlength:0x56, handle:0x5C8, path:"\REG
ISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\Cry
ptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.4"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtClose, status:0x0, handle:0x5
C8
pid:4092, tid:1488, tick:0x33D7280, lvl:LOG, func:NtEnumerateKey, status:0x80000
01A, index:0x7, class:0x0, length:0x120, resultlength:0x0, handle:0x564, path:"\
REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\
CryptDllDecodeObjectEx"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtClose, status:0x0, handle:0x5
64
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtClose, status:0x0, handle:0x5
74
pid:4092, tid:1488, tick:0x33D7280, lvl:LOG, func:NtEnumerateKey, status:0x80000
01A, index:0x2, class:0x0, length:0x120, resultlength:0x0, handle:0x538, path:"\
REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtClose, status:0x0, handle:0x5
38
pid:4092, tid:8264, tick:0x33D7280, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Certific
ate\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtClose, status:0x0, handle:0x5
A8
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"$Function", class:0x2, length:0x90, resultlength:0x38, handle:0x674, path:"\
REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Cer
tificate\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}"
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtClose, status:0x0, handle:0x6
74
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x5A8, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptography\
Providers\Trust\FinalPolicy\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"$DLL", class:0x2, length:0x90, resultlength:0x4E, handle:0x5A8, path:"\REGIS
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\FinalPol
icy\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}"
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x674, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptography\
Providers\Trust\FinalPolicy\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"$Function", class:0x2, length:0x90, resultlength:0x2A, handle:0x5A8, path:"\
REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Fin
alPolicy\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtClose, status:0x0, handle:0x5
A8
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"$DLL", class:0x2, length:0x90, resultlength:0x4E, handle:0x674, path:"\REGIS
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\FinalPol
icy\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}"
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"$Function", class:0x2, length:0x90, resultlength:0x2A, handle:0x674, path:"\
REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Fin
alPolicy\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x5A8, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptography\
Providers\Trust\Initialization\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"$DLL", class:0x2, length:0x90, resultlength:0x4E, handle:0x5A8, path:"\REGIS
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Initiali
zation\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}"
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtClose, status:0x0, handle:0x6
74
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"$Function", class:0x2, length:0x90, resultlength:0x30, handle:0x5A8, path:"\
REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Ini
tialization\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtClose, status:0x0, handle:0x5
A8
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x538, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptography\
Providers\Trust\Initialization\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x674, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptography\
Providers\Trust\Message\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}"
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"$DLL", class:0x2, length:0x90, resultlength:0x4E, handle:0x538, path:"\REGIS
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Initiali
zation\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtQueryValueKey, status:0x0, na
74
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"$Function", class:0x2, length:0x90, resultlength:0x36, handle:0x574, path:"\
REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Sig
nature\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}"
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtClose, status:0x0, handle:0x5
74
pid:4092, tid:1488, tick:0x33D7280, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptog
raphy\Providers\Trust\DiagnosticPolicy\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}"
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x660, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptography\
Providers\Trust\CertCheck\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x574, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptography\
Providers\Trust\Cleanup\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}"
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"$DLL", class:0x2, length:0x90, resultlength:0x4E, handle:0x660, path:"\REGIS
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\CertChec
k\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"$DLL", class:0x2, length:0x90, resultlength:0x4E, handle:0x574, path:"\REGIS
TRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Cleanup\
{573E31F8-AABA-11D0-8CCB-00C04FC295EE}"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"$Function", class:0x2, length:0x90, resultlength:0x2A, handle:0x574, path:"\
REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Cle
anup\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtClose, status:0x0, handle:0x5
74
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"$Function", class:0x2, length:0x90, resultlength:0x2E, handle:0x660, path:"\
REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Cer
tCheck\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:NtWaitForMultipleObjects, statu
s:0x0, count:0x2, type:0x0, alertable:0x0, objects:0x5CC;0x5E4
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtClose, status:0x0, handle:0x6
60
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"C:\Windows\SysWOW64\WINTRUST.DLL", handle:0x74960000
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"C:\Windows\SysWOW64\WINTRUST.DLL", handle:0x74960000
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"C:\Windows\SysWOW64\WINTRUST.DLL", handle:0x74960000
pid:4092, tid:8264, tick:0x33D7280, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptog
raphy\Providers\Trust\DiagnosticPolicy\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"C:\Windows\SysWOW64\WINTRUST.DLL", handle:0x74960000
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"C:\Windows\SysWOW64\WINTRUST.DLL", handle:0x74960000
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"C:\Windows\SysWOW64\WINTRUST.DLL", handle:0x74960000
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"C:\Windows\SysWOW64\WINTRUST.DLL", handle:0x74960000
pid:4092, tid:8264, tick:0x33D7280, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x574, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptography\
Providers\Trust\Cleanup\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}"
pid:4092, tid:1488, tick:0x33D7280, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74960000, name:"HTTPSCertificateTrust", ordinal:0x0, addr
7-2463990887-1001\Software\Policies\Microsoft\SystemCertificates\TrustedPublishe
r\Safer"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x5
74
pid:4092, tid:1488, tick:0x33D728F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\SystemC
ertificates\TrustedPublisher\Safer"
pid:4092, tid:8264, tick:0x33D728F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x538, access:0x2000000, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-24
63990887-1001"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x574, access:0x20019, path:"\REGISTRY\MACHINE\SYSTEM\CurrentControlSet\Service
s\crypt32"
pid:4092, tid:1488, tick:0x33D728F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DiagLevel", class:0x2, length:0x90, resultlength:0x0, handle:0x574,
path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\crypt32"
pid:4092, tid:1488, tick:0x33D728F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"DiagMatchAnyMask", class:0x2, length:0x90, resultlength:0x0, handle:
0x574, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\crypt32"
pid:4092, tid:8264, tick:0x33D728F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x67C, access:0x20019, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463
990887-1001\Software\Microsoft\Internet Explorer\Security"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x5
74
pid:4092, tid:8264, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x5
38
pid:4092, tid:8264, tick:0x33D728F, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"Safety Warning Level", class:0x2, length:0x90, resultlength:0x18, handle:0x6
7C, path:"\REGISTRY\USER\S-1-5-21-2360094602-2602383397-2463990887-1001\SOFTWARE
\Microsoft\Internet Explorer\Security"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x574, access:0x20019, path:"\REGISTRY\MACHINE\SYSTEM\CurrentControlSet\Service
s\crypt32"
pid:4092, tid:8264, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
7C
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtNotifyChangeKey, status:0x103
, event:0x678, iostatus:0x103, information:0x0, filter:0x10000004, watch:0x0, le
ngth:0x0, async:0x1, handle:0x574, path:"\REGISTRY\MACHINE\SYSTEM\ControlSet001\
Services\crypt32"
pid:4092, tid:8264, tick:0x33D728F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Policies\Microsof
t\SystemCertificates\TrustedPublisher\Safer"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x684, iocompletion:0x660, handle:0x680
pid:4092, tid:8264, tick:0x33D728F, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x688, c
lass:0x1, length:0x100, returnlength:0x24, sid:"S-1-5-21-2360094602-2602383397-2
463990887-1001", attributes:0x0
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x690, iocompletion:0x660, handle:0x68C
pid:4092, tid:8264, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
88
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x67C, iocompletion:0x660, handle:0x678
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
88
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
94
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x694, c
iseCertificates\CA\PhysicalStores"
pid:4092, tid:1488, tick:0x33D728F, lvl:LOG, func:NtCreateKey, status:0xC0000022
, handle:0x0, access:0x3001F, title:0x0, class:"", options:0x0, disposition:0xFF
FFFFFE, path:"\REGISTRY\MACHINE\Software\Microsoft\EnterpriseCertificates\CA"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtCreateKey, status:0x0, handle
:0x6BC, access:0x2000000, title:0x0, class:"", options:0x0, disposition:0x2, pat
h:"\REGISTRY\MACHINE\Software"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtCreateKey, status:0x0, handle
:0x6C4, access:0x2000000, title:0x0, class:"", options:0x0, disposition:0x2, pat
h:"\REGISTRY\MACHINE\Software\Microsoft"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
BC
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtCreateKey, status:0x0, handle
:0x6BC, access:0x2000000, title:0x0, class:"", options:0x0, disposition:0x2, pat
h:"\REGISTRY\MACHINE\Software\Microsoft\EnterpriseCertificates"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
C4
pid:4092, tid:1488, tick:0x33D728F, lvl:LOG, func:NtCreateKey, status:0xC0000022
, handle:0x0, access:0x3001F, title:0x0, class:"", options:0x0, disposition:0x2,
path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\EnterpriseCertificates\CA"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
BC
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x6BC, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\EnterpriseCer
tificates\CA"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
BC
pid:4092, tid:1488, tick:0x33D728F, lvl:LOG, func:NtCreateKey, status:0xC0000022
, handle:0x0, access:0x3001F, title:0x0, class:"", options:0x0, disposition:0x1,
path:"\REGISTRY\MACHINE\Software\Microsoft\EnterpriseCertificates\CA"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtCreateKey, status:0x0, handle
:0x6BC, access:0x2000000, title:0x0, class:"", options:0x0, disposition:0x2, pat
h:"\REGISTRY\MACHINE\Software"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtCreateKey, status:0x0, handle
:0x6C4, access:0x2000000, title:0x0, class:"", options:0x0, disposition:0x2, pat
h:"\REGISTRY\MACHINE\Software\Microsoft"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
BC
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtCreateKey, status:0x0, handle
:0x6BC, access:0x2000000, title:0x0, class:"", options:0x0, disposition:0x2, pat
h:"\REGISTRY\MACHINE\Software\Microsoft\EnterpriseCertificates"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
C4
pid:4092, tid:1488, tick:0x33D728F, lvl:LOG, func:NtCreateKey, status:0xC0000022
, handle:0x0, access:0x3001F, title:0x0, class:"", options:0x0, disposition:0x2,
path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\EnterpriseCertificates\CA"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
BC
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x6BC, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\EnterpriseCer
tificates\CA"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x6C4, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\EnterpriseCer
tificates\CA\"
pid:4092, tid:1488, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
BC
pid:4092, tid:1488, tick:0x33D728F, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"AutoFlags", class:0x2, length:0x90, resultlength:0x64, handle:0x6A0,
path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Cryptography\OID\EncodingType 0\Cert
DllCreateCertificateChainEngine\Config"
tDllVerifyRevocation\DEFAULT"
pid:4092, tid:8264, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
64
pid:4092, tid:8264, tick:0x33D728F, lvl:LOG, func:NtEnumerateKey, status:0x80000
01A, index:0x1, class:0x0, length:0x120, resultlength:0x0, handle:0x668, path:"\
REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\
CertDllVerifyRevocation"
pid:4092, tid:8264, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
68
pid:4092, tid:8264, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
B8
pid:4092, tid:8264, tick:0x33D728F, lvl:LOG, func:NtEnumerateKey, status:0x80000
01A, index:0x2, class:0x0, length:0x120, resultlength:0x0, handle:0x698, path:"\
REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID"
pid:4092, tid:8264, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
98
pid:4092, tid:8264, tick:0x33D728F, lvl:LOG, func:NtOpenSection, status:0xC00000
34, handle:0x0, access:0xF, path:"\KnownDlls32\cryptnet.dll"
pid:4092, tid:8264, tick:0x33D728F, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x20, path:"C:\Windows\SYSTEM32\cryptnet.dll"
pid:4092, tid:8264, tick:0x33D728F, lvl:OK, func:NtOpenFile, status:0x0, handle:
0x6D4, access:0x100021, iostatus:0x0, information:0x1, share:0x5, options:0x60,
path:"C:\Windows\SYSTEM32\cryptnet.dll"
pid:4092, tid:8264, tick:0x33D728F, lvl:OK, func:NtCreateSection, status:0x0, ha
ndle:0x6D8, access:0xF, pageattribs:0x10, sectionattribs:0x1000000, file:0x6D4
pid:4092, tid:8264, tick:0x33D728F, lvl:OK, func:NtMapViewOfSection, status:0x0,
address:0x60BF0000, zerobits:0x0, commitsize:0x0, viewsize:0x25000, disposition
:0x1, type:0x800000, protect:0x4, handle:0x6D8, path:"C:\Windows\SYSTEM32\cryptn
et.dll"
pid:4092, tid:8264, tick:0x33D728F, lvl:OK, func:NtClose, status:0x0, handle:0x6
D8
pid:4092, tid:8264, tick:0x33D729F, lvl:OK, func:NtClose, status:0x0, handle:0x6
D4
pid:4092, tid:8264, tick:0x33D729F, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x2, module:"C:\Windows\SYSTEM32\cryptnet.dll", handle:0x60BF0000
pid:4092, tid:8264, tick:0x33D729F, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x2, module:"C:\Windows\SYSTEM32\cryptnet.dll", handle:0x60BF0000
pid:4092, tid:8264, tick:0x33D729F, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x2, module:"C:\Windows\SYSTEM32\cryptnet.dll", handle:0x60BF0000
pid:4092, tid:8264, tick:0x33D729F, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x2, module:"C:\Windows\SYSTEM32\cryptnet.dll", handle:0x60BF0000
pid:4092, tid:8264, tick:0x33D729F, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x2, module:"C:\Windows\SYSTEM32\cryptnet.dll", handle:0x60BF0000
pid:4092, tid:8264, tick:0x33D729F, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x2, module:"C:\Windows\SYSTEM32\cryptnet.dll", handle:0x60BF0000
pid:4092, tid:8264, tick:0x33D729F, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x2, module:"C:\Windows\SYSTEM32\cryptnet.dll", handle:0x60BF0000
pid:4092, tid:8264, tick:0x33D729F, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x2, module:"C:\Windows\SYSTEM32\cryptnet.dll", handle:0x60BF0000
pid:4092, tid:8264, tick:0x33D729F, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x2, module:"C:\Windows\SYSTEM32\cryptnet.dll", handle:0x60BF0000
pid:4092, tid:8264, tick:0x33D729F, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x2, module:"C:\Windows\SYSTEM32\cryptnet.dll", handle:0x60BF0000
pid:4092, tid:8264, tick:0x33D729F, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x2, module:"C:\Windows\SYSTEM32\cryptnet.dll", handle:0x60BF0000
pid:4092, tid:8264, tick:0x33D729F, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptog
raphy\TVO"
pid:4092, tid:8264, tick:0x33D729F, lvl:OK, func:LdrLoadDll, status:0x0, flags:0
x0, module:"C:\Windows\SysWOW64\cryptnet.dll", handle:0x60BF0000
ryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.1.1"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryKey, status:0x0, class:0
x4, length:0xB0, resultlength:0x28, handle:0x6E0, path:"\REGISTRY\MACHINE\SOFTWA
RE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\
1.2.840.113549.1.9.16.1.1"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtEnumerateValueKey, status:0x0
, index:0x0, class:0x1, length:0xDC, resultlength:0x62, handle:0x6E0, path:"\REG
ISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\Cry
ptDllEncodeObjectEx\1.2.840.113549.1.9.16.1.1"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtEnumerateValueKey, status:0x0
, index:0x1, class:0x1, length:0xDC, resultlength:0x4E, handle:0x6E0, path:"\REG
ISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\Cry
ptDllEncodeObjectEx\1.2.840.113549.1.9.16.1.1"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtClose, status:0x0, handle:0x6
E0
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1, class:0x0, length:0x120, resultlength:0x42, handle:0x6DC, path:"\REGISTR
Y\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDl
lEncodeObjectEx"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x69C, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\C
ryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.1"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryKey, status:0x0, class:0
x4, length:0xB0, resultlength:0x28, handle:0x69C, path:"\REGISTRY\MACHINE\SOFTWA
RE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\
1.2.840.113549.1.9.16.2.1"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtEnumerateValueKey, status:0x0
, index:0x0, class:0x1, length:0xDC, resultlength:0x62, handle:0x69C, path:"\REG
ISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\Cry
ptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.1"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtEnumerateValueKey, status:0x0
, index:0x1, class:0x1, length:0xDC, resultlength:0x5C, handle:0x69C, path:"\REG
ISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\Cry
ptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.1"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtClose, status:0x0, handle:0x6
9C
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x2, class:0x0, length:0x120, resultlength:0x44, handle:0x6DC, path:"\REGISTR
Y\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDl
lEncodeObjectEx"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x69C, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\C
ryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.11
"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryKey, status:0x0, class:0
x4, length:0xB0, resultlength:0x28, handle:0x69C, path:"\REGISTRY\MACHINE\SOFTWA
RE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\
1.2.840.113549.1.9.16.2.11"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtEnumerateValueKey, status:0x0
, index:0x0, class:0x1, length:0xDC, resultlength:0x62, handle:0x69C, path:"\REG
ISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\Cry
ptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.11"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtEnumerateValueKey, status:0x0
, index:0x1, class:0x1, length:0xDC, resultlength:0x62, handle:0x69C, path:"\REG
ISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\Cry
ptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.11"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtClose, status:0x0, handle:0x6
9C
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x3, class:0x0, length:0x120, resultlength:0x44, handle:0x6DC, path:"\REGISTR
Y\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDl
lEncodeObjectEx"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x69C, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\C
ryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.12
"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryKey, status:0x0, class:0
x4, length:0xB0, resultlength:0x28, handle:0x69C, path:"\REGISTRY\MACHINE\SOFTWA
RE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\
1.2.840.113549.1.9.16.2.12"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtEnumerateValueKey, status:0x0
, index:0x0, class:0x1, length:0xDC, resultlength:0x62, handle:0x69C, path:"\REG
ISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\Cry
ptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.12"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtEnumerateValueKey, status:0x0
, index:0x1, class:0x1, length:0xDC, resultlength:0x5E, handle:0x69C, path:"\REG
ISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\Cry
ptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.12"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtClose, status:0x0, handle:0x6
9C
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x4, class:0x0, length:0x120, resultlength:0x42, handle:0x6DC, path:"\REGISTR
Y\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDl
lEncodeObjectEx"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x69C, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\C
ryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.2"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryKey, status:0x0, class:0
x4, length:0xB0, resultlength:0x28, handle:0x69C, path:"\REGISTRY\MACHINE\SOFTWA
RE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\
1.2.840.113549.1.9.16.2.2"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtEnumerateValueKey, status:0x0
, index:0x0, class:0x1, length:0xDC, resultlength:0x62, handle:0x69C, path:"\REG
ISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\Cry
ptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.2"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtEnumerateValueKey, status:0x0
, index:0x1, class:0x1, length:0xDC, resultlength:0x5A, handle:0x69C, path:"\REG
ISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\Cry
ptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.2"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtClose, status:0x0, handle:0x6
9C
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x5, class:0x0, length:0x120, resultlength:0x42, handle:0x6DC, path:"\REGISTR
Y\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDl
lEncodeObjectEx"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x69C, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\C
ryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.3"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryKey, status:0x0, class:0
x4, length:0xB0, resultlength:0x28, handle:0x69C, path:"\REGISTRY\MACHINE\SOFTWA
RE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\
1.2.840.113549.1.9.16.2.3"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtEnumerateValueKey, status:0x0
, index:0x0, class:0x1, length:0xDC, resultlength:0x62, handle:0x69C, path:"\REG
ISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\Cry
ptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.3"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtEnumerateValueKey, status:0x0
, index:0x1, class:0x1, length:0xDC, resultlength:0x52, handle:0x69C, path:"\REG
ISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\Cry
ptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.3"
9C
pid:4092, tid:1488, tick:0x33D729F, lvl:LOG, func:NtEnumerateKey, status:0x80000
01A, index:0x2, class:0x0, length:0x120, resultlength:0x0, handle:0x6DC, path:"\
REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\
CryptDllFindOIDInfo"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtClose, status:0x0, handle:0x6
DC
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtClose, status:0x0, handle:0x6
70
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtClose, status:0x0, handle:0x5
F4
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x5F4, access:0x20119, path:"\REGISTRY\MACHINE\SYSTEM\CurrentControlSet\Control
\Cryptography\ECCParameters"
pid:4092, tid:1488, tick:0x33D729F, lvl:LOG, func:NtEnumerateKey, status:0x80000
01A, index:0x0, class:0x0, length:0x120, resultlength:0x0, handle:0x5F4, path:"\
REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Cryptography\ECCParameters"
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtClose, status:0x0, handle:0x5
F4
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory, status:0x
0, address:0x2DBEAA8, class:0x3, length:0x14
pid:4092, tid:1488, tick:0x33D729F, lvl:OK, func:NtQueryVirtualMemory, status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
status:0x
OID"
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x0, class:0x0, length:0x120, resultlength:0x2C, handle:0x670, path:"\REGISTR
Y\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID"
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x5F4, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\C
ryptography\OID\EncodingType 0"
pid:4092, tid:1488, tick:0x33D72AF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Micro
soft\Cryptography\OID\EncodingType 0\CryptDllImportPublicKeyInfoEx2"
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtClose, status:0x0, handle:0x5
F4
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1, class:0x0, length:0x120, resultlength:0x2C, handle:0x670, path:"\REGISTR
Y\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID"
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x5F4, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\C
ryptography\OID\EncodingType 1"
pid:4092, tid:1488, tick:0x33D72AF, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Micro
soft\Cryptography\OID\EncodingType 1\CryptDllImportPublicKeyInfoEx2"
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtClose, status:0x0, handle:0x5
F4
pid:4092, tid:1488, tick:0x33D72AF, lvl:LOG, func:NtEnumerateKey, status:0x80000
01A, index:0x2, class:0x0, length:0x120, resultlength:0x0, handle:0x670, path:"\
REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID"
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtClose, status:0x0, handle:0x6
70
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, iostatus:0x0, information:0x118, code:0x390402, inlen:0x38, outlen:0x180, ha
ndle:0x340, path:"\Device\KsecDD"
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:LdrGetProcedureAddressForCaller
, status:0x0, module:0x74AB0000, name:"GetAsymmetricEncryptionInterface", ordina
l:0x0, address:0x74ADC770, image:0x0, caller:0x72B3146B
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x6E0, access:0x20119, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptography\
OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config"
pid:4092, tid:1488, tick:0x33D72AF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"CryptnetPreFetchMinMaxAgeSeconds", class:0x2, length:0x90, resultlen
gth:0x0, handle:0x6E0, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Cryptography\O
ID\EncodingType 0\CertDllCreateCertificateChainEngine\Config"
pid:4092, tid:1488, tick:0x33D72AF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"CryptnetPreFetchMaxMaxAgeSeconds", class:0x2, length:0x90, resultlen
gth:0x0, handle:0x6E0, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Cryptography\O
ID\EncodingType 0\CertDllCreateCertificateChainEngine\Config"
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtClose, status:0x0, handle:0x6
E0
pid:4092, tid:8264, tick:0x33D72AF, lvl:OK, func:NtWaitForMultipleObjects, statu
s:0x0, count:0x2, type:0x1, alertable:0x0, objects:0x6D8;0x6D4
pid:4092, tid:8264, tick:0x33D72AF, lvl:OK, func:NtClose, status:0x0, handle:0x6
D8
pid:4092, tid:8264, tick:0x33D72AF, lvl:OK, func:NtClose, status:0x0, handle:0x6
D4
pid:4092, tid:1488, tick:0x33D72AF, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x6E0, access:0x20119, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptography\
OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config"
pid:4092, tid:1488, tick:0x33D72AF, lvl:LOG, func:NtQueryValueKey, status:0xC000
0034, name:"CryptnetCachedOcspSwitchToCrlCount", class:0x2, length:0x90, resultl
ength:0x0, handle:0x6E0, path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Cryptography
\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config"
\S-1-5-21-2360094602-2602383397-2463990887-1001"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"ProfileImagePath", class:0x2, length:0x90, resultlength:0x30, handle:0x6CC,
path:"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\ProfileList
\S-1-5-21-2360094602-2602383397-2463990887-1001"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtClose, status:0x0, handle:0x6
CC
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtClose, status:0x0, handle:0x6
9C
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtClose, status:0x0, handle:0x5
F4
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtQueryAttributesFile, status:0
x0, attribs:0x2010, path:"C:\Users\i92segoa\AppData\LocalLow"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtOpenFile, status:0x0, handle:
0x69C, access:0x20000, iostatus:0x0, information:0x1, share:0x7, options:0x20000
0, path:"C:\Users\i92segoa\AppData\LocalLow"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtQuerySecurityObject, status:0
x0, class:0x10, length:0x400, requiredlength:0x30, handle:0x69C, path:"C:\Users\
i92segoa\AppData\LocalLow"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtClose, status:0x0, handle:0x6
9C
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtClose, status:0x0, handle:0x6
70
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtCreateFile, status:0x0, handl
e:0x670, access:0x80100080, iostatus:0x0, information:0x1, attribs:0x80, share:0
x1, disposition:0x1, options:0x60, path:"C:\Users\i92segoa\AppData\LocalLow\Micr
osoft\CryptnetUrlCache\MetaData\024823B39FBEACCDB5C06426A8168E99_4EB65D2EF896F9A
30A10A7F798B64304"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtCreateFile, status:0x0, handl
e:0x6E0, access:0x80100080, iostatus:0x0, information:0x1, attribs:0x80, share:0
x1, disposition:0x1, options:0x60, path:"C:\Users\i92segoa\AppData\LocalLow\Micr
osoft\CryptnetUrlCache\Content\024823B39FBEACCDB5C06426A8168E99_4EB65D2EF896F9A3
0A10A7F798B64304"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtQueryInformationFile, status:
0x0, iostatus:0x0, information:0x18, length:0x18, class:0x5, handle:0x670, path:
"C:\Users\i92segoa\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\024823B3
9FBEACCDB5C06426A8168E99_4EB65D2EF896F9A30A10A7F798B64304"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtReadFile, status:0x0, iostatu
s:0x0, information:0x4, length:0x4, handle:0x670, path:"C:\Users\i92segoa\AppDat
a\LocalLow\Microsoft\CryptnetUrlCache\MetaData\024823B39FBEACCDB5C06426A8168E99_
4EB65D2EF896F9A30A10A7F798B64304"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtReadFile, status:0x0, iostatu
s:0x0, information:0x6C, length:0x6C, handle:0x670, path:"C:\Users\i92segoa\AppD
ata\LocalLow\Microsoft\CryptnetUrlCache\MetaData\024823B39FBEACCDB5C06426A8168E9
9_4EB65D2EF896F9A30A10A7F798B64304"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtReadFile, status:0x0, iostatu
s:0x0, information:0x124, length:0x124, handle:0x670, path:"C:\Users\i92segoa\Ap
pData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\024823B39FBEACCDB5C06426A8168
E99_4EB65D2EF896F9A30A10A7F798B64304"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtReadFile, status:0x0, iostatu
s:0x0, information:0x1D8, length:0x1D8, handle:0x6E0, path:"C:\Users\i92segoa\Ap
pData\LocalLow\Microsoft\CryptnetUrlCache\Content\024823B39FBEACCDB5C06426A8168E
99_4EB65D2EF896F9A30A10A7F798B64304"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtClose, status:0x0, handle:0x6
E0
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtClose, status:0x0, handle:0x6
70
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtDeviceIoControlFile, status:0
x0, iostatus:0x0, information:0xE0, code:0x390402, inlen:0x40, outlen:0x180, han
dle:0x340, path:"\Device\KsecDD"
"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Cryptography"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtQueryValueKey, status:0x0, na
me:"MachineGuid", class:0x2, length:0x90, resultlength:0x56, handle:0x6E0, path:
"\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\Cryptography"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtClose, status:0x0, handle:0x6
E0
pid:4092, tid:1488, tick:0x33D72CE, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptog
raphy\Offload"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:New_NtQueryInformationToken::<l
ambda_7138ae5cd59c00b0ddad740776ba328b>::operator (), status:0x0, token:0x6E0, c
lass:0x1, length:0x400, returnlength:0x24, sid:"S-1-5-21-2360094602-2602383397-2
463990887-1001", attributes:0x0
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtClose, status:0x0, handle:0x6
E0
pid:4092, tid:1488, tick:0x33D72CE, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptog
raphy\DESHashSessionKeyBackward"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtClose, status:0x0, handle:0x6
70
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x670, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptography\
OID"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x0, class:0x0, length:0x120, resultlength:0x2C, handle:0x670, path:"\REGISTR
Y\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x6E0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\C
ryptography\OID\EncodingType 0"
pid:4092, tid:1488, tick:0x33D72CE, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Micro
soft\Cryptography\OID\EncodingType 0\CryptDllImportPublicKeyInfoEx"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtClose, status:0x0, handle:0x6
E0
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x1, class:0x0, length:0x120, resultlength:0x2C, handle:0x670, path:"\REGISTR
Y\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x6E0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\C
ryptography\OID\EncodingType 1"
pid:4092, tid:1488, tick:0x33D72CE, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
, handle:0x0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Micro
soft\Cryptography\OID\EncodingType 1\CryptDllImportPublicKeyInfoEx"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtClose, status:0x0, handle:0x6
E0
pid:4092, tid:1488, tick:0x33D72CE, lvl:LOG, func:NtEnumerateKey, status:0x80000
01A, index:0x2, class:0x0, length:0x120, resultlength:0x0, handle:0x670, path:"\
REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtClose, status:0x0, handle:0x6
70
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x670, access:0x20019, path:"\REGISTRY\MACHINE\Software\Microsoft\Cryptography\
OID"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtEnumerateKey, status:0x0, ind
ex:0x0, class:0x0, length:0x120, resultlength:0x2C, handle:0x670, path:"\REGISTR
Y\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID"
pid:4092, tid:1488, tick:0x33D72CE, lvl:OK, func:NtOpenKeyEx, status:0x0, handle
:0x6E0, access:0x20019, path:"\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\C
ryptography\OID\EncodingType 0"
pid:4092, tid:1488, tick:0x33D72CE, lvl:LOG, func:NtOpenKeyEx, status:0xC0000034
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:3336, tick:0x33DAD66, lvl:OK, func:NtWaitForMultipleObjects, statu
s:0x102, count:0x1, type:0x1, alertable:0x0, timeout:0xFFFFFFFFF70F2E80, objects
:0x6D4
pid:4092, tid:8264, tick:0x33DAE8F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33DAE8F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33DB277, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33DB277, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33DB65F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33DB65F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33DBA47, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33DBA47, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33DBE2F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33DBE2F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33DC217, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33DC217, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33DC5FF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33DC5FF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33DC9E7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33DC9E7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33DCDCF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33DCDCF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33DD1B7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33DD1B7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33DD59F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33DD59F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33DD987, lvl:OK, func:NtAssociateWaitCompletionPacket
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33F743B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33F743B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33F7833, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33F7833, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33F7C1B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33F7C1B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33F8003, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33F8003, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33F83EB, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33F83EB, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33F87E3, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33F87E3, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33F8BCB, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33F8BCB, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33F8FB3, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33F8FB3, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33F93AA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33F93AA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33F9792, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33F9792, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33F9B8A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33F9B8A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33F9F82, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33F9F82, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33FA36A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33FA36A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33FA752, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33FA752, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33FAB49, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33FAB49, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33FAF41, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33FAF41, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33FB329, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33FB329, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:8264, tick:0x33FB711, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:8264, tick:0x33FB711, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x33FB9EF, lvl:OK, func:LdrUnloadDll, status:0x0, handl
e:0x74760000
pid:4092, tid:1488, tick:0x33FB9EF, lvl:OK, func:NtClose, status:0x0, handle:0x4
74
pid:4092, tid:1488, tick:0x33FBAF9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x33FBAF9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x33FBEF0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x33FBEF0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x33FC2D8, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x33FC2D8, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x33FC6D0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x33FC6D0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x33FCAC8, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x33FCAC8, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3405862, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3405862, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3405C4A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3405C4A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3406041, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3406041, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3406429, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3406429, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3406821, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3406821, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3406C09, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3406C09, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3407001, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3407001, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34073E9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34073E9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x34077D1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x34077D1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3407BB9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3407BB9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3407FB0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3407FB0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3408398, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3408398, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3408780, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3408780, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3408B78, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3408B78, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3408F60, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3408F60, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3409348, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3409348, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3409730, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3409730, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3409B27, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3409B27, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x3409F0F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x3409F0F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x340A2F7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x340A2F7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x340A6DF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x340A6DF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x340AAD7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x340AAD7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x340AEBF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x340AEBF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x340B2A7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x340B2A7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x340B69F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x340B69F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x340BA87, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x340BA87, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x340BE7E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x340BE7E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x340C276, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x340C276, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x340C65E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x340C65E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x340CA56, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x340CA56, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x340CB6F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x340CE3E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x340CE3E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x340D235, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x340D235, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x340D61D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x340D61D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x340DA05, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x340DA05, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x340DDFD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1488, tick:0x340DDFD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1488, tick:0x340E1E5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x361FD0D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x361FD0D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36200F5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36200F5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36204DD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36204DD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36208D5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36208D5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3620CBD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3620CBD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36210A5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36210A5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x362148D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x362148D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3621875, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3621875, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3621C5D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3621C5D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3622045, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3622045, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x362242D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x362242D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3622815, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3622815, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3622BFD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3622BFD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3622FE5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3622FE5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36233CD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36233CD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36237B5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36237B5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3623B9D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3623B9D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3623F85, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3623F85, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x362436D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x362436D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3624755, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3624755, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3624B3D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3624B3D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3624F25, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3624F25, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x362530D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x362530D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36256F5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36256F5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3625ADD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3625ADD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3625EC5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3625EC5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36262AD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36262AD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3626695, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3626695, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3626A7D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3626A7D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3626E65, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3626E65, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x362724D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x362724D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3627645, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3627645, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3627A2D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3627A2D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3627E15, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3627E15, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36281FD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36281FD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36285E5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36285E5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36289CD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36289CD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3628DB5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3628DB5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x362919D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x362919D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3629585, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3629585, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x362996D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x362996D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3629D55, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3629D55, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x362A13D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x362A13D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x362A525, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x362A525, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x362A90D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x362A90D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x362ACF5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x362ACF5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x362B0DD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x362B0DD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x362B4C5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x362B4C5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x362B8AD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x362B8AD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x362BC95, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x362BC95, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x362C07D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x362C07D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x362C465, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x362C465, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x362C84D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x362C84D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x362CC35, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x362CC35, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x362D01D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x362D01D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x362D405, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x362D405, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x362D7ED, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x362D7ED, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x362DBD5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x362DBD5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x362DFBD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x362DFBD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x362E3A5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x362E3A5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x362E78D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x362E78D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x362EB75, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x362EB75, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x362EF5D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x362EF5D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x362F345, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x362F345, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x362F73C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x362F73C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x362FB24, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x362FB24, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x362FF0C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x362FF0C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36302F4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36302F4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36306DC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36306DC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3630AC4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3630AC4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3630EAC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3630EAC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3631294, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3631294, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x363167C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x363167C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3631A64, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3631A64, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3631E4C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3631E4C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3632234, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3632234, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x363261C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x363261C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3632A04, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3632A04, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3632DEC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3632DEC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36331D4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36331D4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36335BC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36335BC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36339A4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36339A4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3633D8C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3633D8C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3634174, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3634174, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x363455C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x363455C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3634944, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3634944, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3634D2C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3634D2C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3635114, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3635114, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36354FC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36354FC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36358F4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36358F4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3635CDC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3635CDC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36360C4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36360C4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36364AC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36364AC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3636894, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3636894, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3636C8C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3636C8C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3637074, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3637074, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x363745C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x363745C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3637844, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3637844, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3637C2C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3637C2C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3638014, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3638014, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36383FC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36383FC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36387F3, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36387F3, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3638BEB, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3638BEB, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3638FD3, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3638FD3, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36393BB, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36393BB, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36397B2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36397B2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3639B9A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3639B9A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3639F92, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3639F92, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x363A37A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x363A37A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x363A762, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x363A762, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x363AB4A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x363AB4A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x363AF42, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x363AF42, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x363B32A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x363B32A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x363B712, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x363B712, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x363BAFA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x363BAFA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x363BEE2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x363BEE2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x363C2D9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x363C2D9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x363C6D1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x363C6D1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x363CAB9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x363CAB9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x363CEA1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x363CEA1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x363D289, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x363D289, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x363D671, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x363D671, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x363DA59, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x363DA59, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x363DE51, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x363DE51, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x363E239, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x363E239, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x363E621, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x363E621, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x363EA09, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x363EA09, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x363EE00, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x363EE00, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x363F1E8, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x363F1E8, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x363F5D0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x363F5D0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x363F9B8, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x363F9B8, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x363FDB0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x363FDB0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3640198, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3640198, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3640580, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3640580, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3640977, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3640977, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3640D5F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3640D5F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3641147, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3641147, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x364152F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x364152F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3641927, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3641927, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3641D0F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3641D0F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36420F7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36420F7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36424EF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36424EF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36428D7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36428D7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3642CBF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3642CBF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36430A7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36430A7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x364348F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x364348F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3643877, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3643877, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3643C6E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3643C6E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3644056, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3644056, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x364443E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x364443E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3644826, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3644826, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3644C0E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3644C0E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3644FF6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3644FF6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36453EE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36453EE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36457D6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36457D6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3645BBE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3645BBE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3645FA6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3645FA6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x364638E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x364638E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3646776, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3646776, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3646B5E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3646B5E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3646F46, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3646F46, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x364732E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x364732E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3647716, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3647716, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3647AFE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3647AFE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3647EF6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3647EF6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36482ED, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36482ED, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36486D5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36486D5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3648ABD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3648ABD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3648EA5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3648EA5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x364929D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x364929D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3649685, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3649685, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3649A6D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3649A6D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3649E55, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3649E55, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x364A23D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x364A23D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x364A634, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x364A634, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x364AA1C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x364AA1C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x364AE14, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x364AE14, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x364B1FC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x364B1FC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x364B5E4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x364B5E4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x364B9CC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x364B9CC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x364BDB4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x364BDB4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x364C19C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x364C19C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x364C584, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x364C584, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x364C97C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x364C97C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x364CD73, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x364CD73, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x364D16B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x364D16B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x364D553, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x364D553, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x364D93B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x364D93B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x364DD33, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x364DD33, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x364E11B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x364E11B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x364E503, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x364E503, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x364E8FA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x364E8FA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x364ECE2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x364ECE2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x364F0CA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x364F0CA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x364F4B2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x364F4B2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x364F8AA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x364F8AA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x364FC92, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x364FC92, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3650089, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3650089, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3650471, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3650471, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3650859, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3650859, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3650C41, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3650C41, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3651039, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3651039, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3651421, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3651421, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3651809, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3651809, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3651BF1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3651BF1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3651FD9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3651FD9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36523C1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36523C1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36527A9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36527A9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3652BA1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3652BA1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3652F89, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3652F89, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3653371, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3653371, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3653768, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3653768, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3653B60, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3653B60, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3653F48, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3653F48, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3654330, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3654330, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3654718, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3654718, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3654B00, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3654B00, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3654EE8, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3654EE8, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36552E0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36552E0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36556D7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36556D7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3655ABF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3655ABF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3655EA7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3655EA7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x365629F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x365629F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3656696, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3656696, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3656A7E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3656A7E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3656E66, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3656E66, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x365724E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x365724E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3657636, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3657636, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3657A1E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3657A1E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3657E06, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3657E06, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36581EE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36581EE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36585D6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36585D6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36589CE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36589CE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3658DB6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3658DB6, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x365919E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x365919E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3659586, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3659586, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x365997E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x365997E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3659D66, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3659D66, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x365A14E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x365A14E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x365A536, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x365A536, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x365A91E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x365A91E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x365AD15, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x365AD15, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x365B0FD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x365B0FD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x365B4E5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x365B4E5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x365B8CD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x365B8CD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x365BCC5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x365BCC5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x365C0AD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x365C0AD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x365C495, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x365C495, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x365C87D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x365C87D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x365CC65, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x365CC65, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x365D04D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x365D04D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x365D435, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x365D435, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x365D81D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x365D81D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x365DC05, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x365DC05, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x365DFFD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x365DFFD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x365E3E5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x365E3E5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x365E7CD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x365E7CD, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x365EBC4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x365EBC4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x365EFAC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x365EFAC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x365F394, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x365F394, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x365F77C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x365F77C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x365FB64, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x365FB64, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x365FF4C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x365FF4C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3660334, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3660334, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x366072C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x366072C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3660B14, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3660B14, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3660EFC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3660EFC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36612E4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36612E4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36616DB, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36616DB, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3661AC3, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3661AC3, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3661EBB, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3661EBB, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36622B3, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36622B3, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x366269B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x366269B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3662A83, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3662A83, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3662E6B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3662E6B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3663262, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3663262, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x366364A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x366364A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3663A32, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3663A32, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3663E1A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3663E1A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3664202, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3664202, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36645FA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36645FA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36649E2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36649E2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3664DCA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3664DCA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36651B2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36651B2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36655AA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36655AA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3665992, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3665992, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3665D89, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3665D89, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3666171, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3666171, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3666559, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3666559, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3666951, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3666951, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3666D39, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3666D39, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3667121, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3667121, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3667518, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3667518, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3667910, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3667910, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3667CF8, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3667CF8, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36680E0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36680E0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36684D8, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36684D8, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36688C0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36688C0, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3668CB7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3668CB7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36690AF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36690AF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3669497, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3669497, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x366987F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x366987F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3669C67, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3669C67, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x366A05F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x366A05F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x366A447, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x366A447, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x366A82F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x366A82F, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x366AC17, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x366AC17, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x366AFFF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x366AFFF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x366B3E7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x366B3E7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x366B7CF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x366B7CF, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x366BBB7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x366BBB7, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x366BFAE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x366BFAE, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x366C396, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x366C396, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x366C77E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x366C77E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x366CB66, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x366CB66, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x366CF5E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x366CF5E, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x366D355, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x366D355, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x366D73D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x366D73D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x366DB35, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x366DB35, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x366DF1D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x366DF1D, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x366E305, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x366E305, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x366E6ED, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x366E6ED, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x366EAE5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x366EAE5, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x366EEDC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x366EEDC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x366F2D4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x366F2D4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x366F6BC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x366F6BC, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x366FAA4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x366FAA4, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x366FE8C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x366FE8C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3670274, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3670274, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x367066C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x367066C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3670A54, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3670A54, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3670E3C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3670E3C, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3671233, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3671233, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x367161B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x367161B, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3671A03, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3671A03, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3671DFB, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3671DFB, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36721E3, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36721E3, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36725CB, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36725CB, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36729B3, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36729B3, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3672DAA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3672DAA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3673192, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3673192, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x367357A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x367357A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3673962, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3673962, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3673D4A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3673D4A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3674132, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3674132, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x367451A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x367451A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3674912, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3674912, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3674CFA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3674CFA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36750E2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36750E2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36754CA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36754CA, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36758B2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36758B2, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3675C9A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3675C9A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3676082, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3676082, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x367646A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x367646A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3676852, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3676852, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3676C4A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3676C4A, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3677041, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3677041, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3677429, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3677429, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3677811, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3677811, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3677BF9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3677BF9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3677FF1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3677FF1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36783D9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36783D9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x36787D1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x36787D1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3678BB9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3678BB9, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3678FA1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3678FA1, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3679389, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3679389, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3679780, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3679780, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3679B68, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3679B68, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x3679F50, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x3679F50, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"
pid:4092, tid:1184, tick:0x367A338, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x4C, iocompletion:0x38, handle:0x48
pid:4092, tid:1184, tick:0x367A338, lvl:OK, func:NtAssociateWaitCompletionPacket
, status:0x0, completionpacket:0x2F0, iocompletion:0x38, handle:0xCC, path:"\Ses
sions\1\BaseNamedObjects\_xvm_evt_notification_0xA527E666CB0D6807"