Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- --------------------------------------------------------------------------------
- Starting profile on 2015-02-25 at 13:48:14
- Operating System: Microsoft Windows XP Professional (32-bit), version 5.01.2600 Dodatek Service Pack 3
- Program Executable: c:\windows\WELCOME.EXE
- Program Arguments:
- Starting Directory: C:\WINDOWS\
- Search Path: C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem
- Options Selected:
- Simulate ShellExecute by inserting any App Paths directories into the PATH environment variable.
- Log DllMain calls for process attach and process detach messages.
- Log DllMain calls for all other messages, including thread attach and thread detach.
- Hook the process to gather more detailed dependency information.
- Log LoadLibrary function calls.
- Log GetProcAddress function calls.
- Log thread information.
- Use simple thread numbers instead of actual thread IDs.
- Log first chance exceptions.
- Log debug output messages.
- Use full paths when logging file names.
- Log a time stamp with each line of log.
- Automatically open and profile child processes.
- --------------------------------------------------------------------------------
- 00:00:00.000: Started "c:\windows\WELCOME.EXE" (process 0x7BC) at address 0x00400000 by thread 1. Successfully hooked module.
- 00:00:00.000: Loaded "c:\windows\system32\NTDLL.DLL" at address 0x7C900000 by thread 1. Successfully hooked module.
- 00:00:00.060: Loaded "c:\windows\system32\KERNEL32.DLL" at address 0x7C800000 by thread 1. Successfully hooked module.
- 00:00:00.060: DllMain(0x7C900000, DLL_PROCESS_ATTACH, 0x00000000) in "c:\windows\system32\NTDLL.DLL" called by thread 1.
- 00:00:00.060: DllMain(0x7C900000, DLL_PROCESS_ATTACH, 0x00000000) in "c:\windows\system32\NTDLL.DLL" returned 1 (0x1) by thread 1.
- 00:00:00.060: DllMain(0x7C800000, DLL_PROCESS_ATTACH, 0x00000000) in "c:\windows\system32\KERNEL32.DLL" called by thread 1.
- 00:00:00.060: DllMain(0x7C800000, DLL_PROCESS_ATTACH, 0x00000000) in "c:\windows\system32\KERNEL32.DLL" returned 1 (0x1) by thread 1.
- 00:00:00.070: Injected "c:\documents and settings\fluttie\pulpit\DEPENDS.DLL" at address 0x08370000 by thread 1.
- 00:00:00.100: DllMain(0x08370000, DLL_PROCESS_ATTACH, 0x00000000) in "c:\documents and settings\fluttie\pulpit\DEPENDS.DLL" called by thread 1.
- 00:00:00.150: DllMain(0x08370000, DLL_PROCESS_ATTACH, 0x00000000) in "c:\documents and settings\fluttie\pulpit\DEPENDS.DLL" returned 1 (0x1) by thread 1.
- 00:00:00.180: Loaded "c:\windows\system32\USER32.DLL" at address 0x7E360000 by thread 1. Successfully hooked module.
- 00:00:00.201: Loaded "c:\windows\system32\GDI32.DLL" at address 0x77F10000 by thread 1. Successfully hooked module.
- 00:00:00.221: Loaded "c:\windows\system32\ADVAPI32.DLL" at address 0x77DC0000 by thread 1. Successfully hooked module.
- 00:00:00.241: Loaded "c:\windows\system32\RPCRT4.DLL" at address 0x77E70000 by thread 1. Successfully hooked module.
- 00:00:00.241: Loaded "c:\windows\system32\SECUR32.DLL" at address 0x77FE0000 by thread 1. Successfully hooked module.
- 00:00:00.281: Loaded "c:\windows\system32\SHELL32.DLL" at address 0x7C9C0000 by thread 1. Successfully hooked module.
- 00:00:00.301: Loaded "c:\windows\system32\MSVCRT.DLL" at address 0x77C00000 by thread 1. Successfully hooked module.
- 00:00:00.321: Loaded "c:\windows\system32\SHLWAPI.DLL" at address 0x77F60000 by thread 1. Successfully hooked module.
- 00:00:00.341: Loaded "c:\windows\system32\WINMM.DLL" at address 0x76B20000 by thread 1. Successfully hooked module.
- 00:00:00.341: Entrypoint reached. All implicit modules have been loaded.
- 00:00:00.351: Loaded "c:\windows\system32\SHIMENG.DLL" at address 0x5CFE0000 by thread 1. Successfully hooked module.
- 00:00:00.381: Loaded "c:\windows\apppatch\ACLAYERS.DLL" at address 0x71620000 by thread 1. Successfully hooked module.
- 00:00:00.431: Loaded "c:\windows\system32\OLE32.DLL" at address 0x774D0000 by thread 1. Successfully hooked module.
- 00:00:00.451: Loaded "c:\windows\system32\USERENV.DLL" at address 0x769A0000 by thread 1. Successfully hooked module.
- 00:00:00.471: Loaded "c:\windows\system32\WINSPOOL.DRV" at address 0x72F90000 by thread 1. Successfully hooked module.
- 00:00:00.481: DllMain(0x71620000, DLL_PROCESS_ATTACH, 0x00000000) in "c:\windows\apppatch\ACLAYERS.DLL" called by thread 1.
- 00:00:00.481: GetProcAddress(0x7C800000 [c:\windows\system32\KERNEL32.DLL], "InitializeCriticalSectionAndSpinCount") called from "c:\windows\apppatch\ACLAYERS.DLL" at address 0x71661BE1 and returned 0x7C80B8B9 by thread 1.
- 00:00:00.491: DllMain(0x71620000, DLL_PROCESS_ATTACH, 0x00000000) in "c:\windows\apppatch\ACLAYERS.DLL" returned 1 (0x1) by thread 1.
- 00:00:00.521: Loaded "c:\windows\apppatch\ACGENRAL.DLL" at address 0x59410000 by thread 1. Successfully hooked module.
- 00:00:00.551: Loaded "c:\windows\system32\OLEAUT32.DLL" at address 0x77110000 by thread 1. Successfully hooked module.
- 00:00:00.571: Loaded "c:\windows\system32\MSACM32.DLL" at address 0x77BD0000 by thread 1. Successfully hooked module.
- 00:00:00.581: Loaded "c:\windows\system32\VERSION.DLL" at address 0x77BF0000 by thread 1. Successfully hooked module.
- 00:00:00.601: Loaded "c:\windows\system32\UXTHEME.DLL" at address 0x5B1D0000 by thread 1. Successfully hooked module.
- 00:00:00.611: DllMain(0x59410000, DLL_PROCESS_ATTACH, 0x00000000) in "c:\windows\apppatch\ACGENRAL.DLL" called by thread 1.
- 00:00:00.611: GetProcAddress(0x7C800000 [c:\windows\system32\KERNEL32.DLL], "InitializeCriticalSectionAndSpinCount") called from "c:\windows\apppatch\ACGENRAL.DLL" at address 0x5943CFF5 and returned 0x7C80B8B9 by thread 1.
- 00:00:00.621: DllMain(0x59410000, DLL_PROCESS_ATTACH, 0x00000000) in "c:\windows\apppatch\ACGENRAL.DLL" returned 1 (0x1) by thread 1.
- 00:00:00.631: GetProcAddress(0x7C900000 [c:\windows\system32\NTDLL.DLL], "RtlAddVectoredExceptionHandler") called from "c:\windows\apppatch\ACLAYERS.DLL" at address 0x71646497 and returned 0x7C936BFA by thread 1.
- 00:00:00.661: GetProcAddress(0x7C800000 [c:\windows\system32\KERNEL32.DLL], "SetDllDirectoryW") called from "c:\windows\apppatch\ACGENRAL.DLL" at address 0x5942B031 and returned 0x7C85FBB8 by thread 1.
- 00:00:00.671: DllMain(0x77F10000, DLL_PROCESS_ATTACH, 0x0013FD30) in "c:\windows\system32\GDI32.DLL" called by thread 1.
- 00:00:00.671: DllMain(0x77F10000, DLL_PROCESS_ATTACH, 0x0013FD30) in "c:\windows\system32\GDI32.DLL" returned 1 (0x1) by thread 1.
- 00:00:00.681: DllMain(0x7E360000, DLL_PROCESS_ATTACH, 0x0013FD30) in "c:\windows\system32\USER32.DLL" called by thread 1.
- 00:00:00.681: DllMain(0x7E360000, DLL_PROCESS_ATTACH, 0x0013FD30) in "c:\windows\system32\USER32.DLL" returned 1 (0x1) by thread 1.
- 00:00:00.681: DllMain(0x77FE0000, DLL_PROCESS_ATTACH, 0x0013FD30) in "c:\windows\system32\SECUR32.DLL" called by thread 1.
- 00:00:00.681: DllMain(0x77FE0000, DLL_PROCESS_ATTACH, 0x0013FD30) in "c:\windows\system32\SECUR32.DLL" returned 1 (0x1) by thread 1.
- 00:00:00.681: DllMain(0x77E70000, DLL_PROCESS_ATTACH, 0x0013FD30) in "c:\windows\system32\RPCRT4.DLL" called by thread 1.
- 00:00:00.681: DllMain(0x77E70000, DLL_PROCESS_ATTACH, 0x0013FD30) in "c:\windows\system32\RPCRT4.DLL" returned 1 (0x1) by thread 1.
- 00:00:00.681: DllMain(0x77DC0000, DLL_PROCESS_ATTACH, 0x0013FD30) in "c:\windows\system32\ADVAPI32.DLL" called by thread 1.
- 00:00:00.681: DllMain(0x77DC0000, DLL_PROCESS_ATTACH, 0x0013FD30) in "c:\windows\system32\ADVAPI32.DLL" returned 1 (0x1) by thread 1.
- 00:00:00.681: DllMain(0x77C00000, DLL_PROCESS_ATTACH, 0x0013FD30) in "c:\windows\system32\MSVCRT.DLL" called by thread 1.
- 00:00:00.691: GetProcAddress(0x7C800000 [c:\windows\system32\KERNEL32.DLL], "InitializeCriticalSectionAndSpinCount") called from "c:\windows\system32\MSVCRT.DLL" at address 0x77C279C2 and returned 0x7C80B8B9 by thread 1.
- 00:00:00.701: DllMain(0x77C00000, DLL_PROCESS_ATTACH, 0x0013FD30) in "c:\windows\system32\MSVCRT.DLL" returned 1 (0x1) by thread 1.
- 00:00:00.701: DllMain(0x77F60000, DLL_PROCESS_ATTACH, 0x0013FD30) in "c:\windows\system32\SHLWAPI.DLL" called by thread 1.
- 00:00:00.701: GetProcAddress(0x7C800000 [c:\windows\system32\KERNEL32.DLL], "CreateTimerQueue") called from "c:\windows\system32\SHLWAPI.DLL" at address 0x77F65CE9 and returned 0x7C82BFCE by thread 1.
- 00:00:00.711: GetProcAddress(0x7C800000 [c:\windows\system32\KERNEL32.DLL], "DeleteTimerQueue") called from "c:\windows\system32\SHLWAPI.DLL" at address 0x77F65CF8 and returned 0x7C863DCB by thread 1.
- 00:00:00.721: GetProcAddress(0x7C800000 [c:\windows\system32\KERNEL32.DLL], "CreateTimerQueueTimer") called from "c:\windows\system32\SHLWAPI.DLL" at address 0x77F65D07 and returned 0x7C821165 by thread 1.
- 00:00:00.721: GetProcAddress(0x7C800000 [c:\windows\system32\KERNEL32.DLL], "ChangeTimerQueueTimer") called from "c:\windows\system32\SHLWAPI.DLL" at address 0x77F65D17 and returned 0x7C8127B3 by thread 1.
- 00:00:00.721: GetProcAddress(0x7C800000 [c:\windows\system32\KERNEL32.DLL], "DeleteTimerQueueTimer") called from "c:\windows\system32\SHLWAPI.DLL" at address 0x77F65D25 and returned 0x7C821118 by thread 1.
- 00:00:00.721: DllMain(0x77F60000, DLL_PROCESS_ATTACH, 0x0013FD30) in "c:\windows\system32\SHLWAPI.DLL" returned 1 (0x1) by thread 1.
- 00:00:00.721: DllMain(0x7C9C0000, DLL_PROCESS_ATTACH, 0x0013FD30) in "c:\windows\system32\SHELL32.DLL" called by thread 1.
- 00:00:00.721: GetProcAddress(0x7C800000 [c:\windows\system32\KERNEL32.DLL], "CreateActCtxW") called from "c:\windows\system32\SHELL32.DLL" at address 0x7CA26B06 and returned 0x7C8154EC by thread 1.
- 00:00:00.741: GetProcAddress(0x7C800000 [c:\windows\system32\KERNEL32.DLL], "ActivateActCtx") called from "c:\windows\system32\SHELL32.DLL" at address 0x7C9E7679 and returned 0x7C80A6D4 by thread 1.
- 00:00:00.741: LoadLibraryW("comctl32.dll") called from "c:\windows\system32\SHELL32.DLL" at address 0x7CA26740 by thread 1.
- 00:00:00.761: Loaded "c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\COMCTL32.DLL" at address 0x773C0000 by thread 1. Successfully hooked module.
- 00:00:00.781: DllMain(0x773C0000, DLL_PROCESS_ATTACH, 0x00000000) in "c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\COMCTL32.DLL" called by thread 1.
- 00:00:00.811: GetProcAddress(0x7C800000 [c:\windows\system32\KERNEL32.DLL], "GetSystemWindowsDirectoryW") called from "c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\COMCTL32.DLL" at address 0x7744B749 and returned 0x7C80ADB9 by thread 1.
- 00:00:00.851: GetProcAddress(0x7C800000 [c:\windows\system32\KERNEL32.DLL], "CreateActCtxW") called from "c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\COMCTL32.DLL" at address 0x7744B5CC and returned 0x7C8154EC by thread 1.
- 00:00:00.881: GetProcAddress(0x7C800000 [c:\windows\system32\KERNEL32.DLL], "ActivateActCtx") called from "c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\COMCTL32.DLL" at address 0x7744B65E and returned 0x7C80A6D4 by thread 1.
- 00:00:00.922: GetProcAddress(0x7C800000 [c:\windows\system32\KERNEL32.DLL], "DeactivateActCtx") called from "c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\COMCTL32.DLL" at address 0x7744B6B4 and returned 0x7C80A705 by thread 1.
- 00:00:00.942: DllMain(0x773C0000, DLL_PROCESS_ATTACH, 0x00000000) in "c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\COMCTL32.DLL" returned 1 (0x1) by thread 1.
- 00:00:00.962: LoadLibraryW("comctl32.dll") returned 0x773C0000 by thread 1.
- 00:00:01.012: GetProcAddress(0x7C800000 [c:\windows\system32\KERNEL32.DLL], "DeactivateActCtx") called from "c:\windows\system32\SHELL32.DLL" at address 0x7C9E76E4 and returned 0x7C80A705 by thread 1.
- 00:00:01.032: LoadLibraryW("comctl32.dll") called from "c:\windows\system32\SHELL32.DLL" at address 0x7CA2686E by thread 1.
- 00:00:01.112: Loaded "c:\windows\system32\COMCTL32.DLL" at address 0x5D520000 by thread 1. Successfully hooked module.
- 00:00:01.142: DllMain(0x5D520000, DLL_PROCESS_ATTACH, 0x00000000) in "c:\windows\system32\COMCTL32.DLL" called by thread 1.
- 00:00:01.172: GetProcAddress(0x7C800000 [c:\windows\system32\KERNEL32.DLL], "InitializeCriticalSectionAndSpinCount") called from "c:\windows\system32\COMCTL32.DLL" at address 0x5D525338 and returned 0x7C80B8B9 by thread 1.
- 00:00:01.212: GetProcAddress(0x7C800000 [c:\windows\system32\KERNEL32.DLL], "CreateActCtxW") called from "c:\windows\system32\COMCTL32.DLL" at address 0x5D58F198 and returned 0x7C8154EC by thread 1.
- 00:00:01.242: GetProcAddress(0x7C800000 [c:\windows\system32\KERNEL32.DLL], "ProcessIdToSessionId") called from "c:\windows\system32\COMCTL32.DLL" at address 0x5D5254D8 and returned 0x7C813019 by thread 1.
- 00:00:01.282: GetProcAddress(0x7E360000 [c:\windows\system32\USER32.DLL], "GetSystemMetrics") called from "c:\windows\system32\COMCTL32.DLL" at address 0x5D5255CE and returned 0x7E368F9C by thread 1.
- 00:00:01.322: GetProcAddress(0x7E360000 [c:\windows\system32\USER32.DLL], "MonitorFromWindow") called from "c:\windows\system32\COMCTL32.DLL" at address 0x5D5255E3 and returned 0x7E37A679 by thread 1.
- 00:00:01.342: GetProcAddress(0x7E360000 [c:\windows\system32\USER32.DLL], "MonitorFromRect") called from "c:\windows\system32\COMCTL32.DLL" at address 0x5D5255F8 and returned 0x7E37C713 by thread 1.
- 00:00:01.372: GetProcAddress(0x7E360000 [c:\windows\system32\USER32.DLL], "MonitorFromPoint") called from "c:\windows\system32\COMCTL32.DLL" at address 0x5D52560D and returned 0x7E37ABF5 by thread 1.
- 00:00:01.402: GetProcAddress(0x7E360000 [c:\windows\system32\USER32.DLL], "EnumDisplayMonitors") called from "c:\windows\system32\COMCTL32.DLL" at address 0x5D525622 and returned 0x7E37A77B by thread 1.
- 00:00:01.442: GetProcAddress(0x7E360000 [c:\windows\system32\USER32.DLL], "EnumDisplayDevicesW") called from "c:\windows\system32\COMCTL32.DLL" at address 0x5D525637 and returned 0x7E36E03C by thread 1.
- 00:00:01.472: GetProcAddress(0x7E360000 [c:\windows\system32\USER32.DLL], "GetMonitorInfoW") called from "c:\windows\system32\COMCTL32.DLL" at address 0x5D525654 and returned 0x7E37A6D9 by thread 1.
- 00:00:01.512: GetProcAddress(0x7C800000 [c:\windows\system32\KERNEL32.DLL], "ActivateActCtx") called from "c:\windows\system32\COMCTL32.DLL" at address 0x5D58F24A and returned 0x7C80A6D4 by thread 1.
- 00:00:01.562: GetProcAddress(0x7C800000 [c:\windows\system32\KERNEL32.DLL], "DeactivateActCtx") called from "c:\windows\system32\COMCTL32.DLL" at address 0x5D58F2AF and returned 0x7C80A705 by thread 1.
- 00:00:01.572: DllMain(0x5D520000, DLL_PROCESS_ATTACH, 0x00000000) in "c:\windows\system32\COMCTL32.DLL" returned 1 (0x1) by thread 1.
- 00:00:01.593: LoadLibraryW("comctl32.dll") returned 0x5D520000 by thread 1.
- 00:00:01.653: GetProcAddress(0x5D520000 [c:\windows\system32\COMCTL32.DLL], "InitCommonControlsEx") called from "c:\windows\system32\SHELL32.DLL" at address 0x7CA2687E and returned 0x5D523619 by thread 1.
- 00:00:01.673: DllMain(0x7C9C0000, DLL_PROCESS_ATTACH, 0x0013FD30) in "c:\windows\system32\SHELL32.DLL" returned 1 (0x1) by thread 1.
- 00:00:01.713: DllMain(0x76B20000, DLL_PROCESS_ATTACH, 0x0013FD30) in "c:\windows\system32\WINMM.DLL" called by thread 1.
- 00:00:01.713: DllMain(0x76B20000, DLL_PROCESS_ATTACH, 0x0013FD30) in "c:\windows\system32\WINMM.DLL" returned 1 (0x1) by thread 1.
- 00:00:01.753: DllMain(0x774D0000, DLL_PROCESS_ATTACH, 0x0013FD30) in "c:\windows\system32\OLE32.DLL" called by thread 1.
- 00:00:01.753: DllMain(0x774D0000, DLL_PROCESS_ATTACH, 0x0013FD30) in "c:\windows\system32\OLE32.DLL" returned 1 (0x1) by thread 1.
- 00:00:01.793: DllMain(0x769A0000, DLL_PROCESS_ATTACH, 0x0013FD30) in "c:\windows\system32\USERENV.DLL" called by thread 1.
- 00:00:01.793: DllMain(0x769A0000, DLL_PROCESS_ATTACH, 0x0013FD30) in "c:\windows\system32\USERENV.DLL" returned 1 (0x1) by thread 1.
- 00:00:01.823: DllMain(0x72F90000, DLL_PROCESS_ATTACH, 0x0013FD30) in "c:\windows\system32\WINSPOOL.DRV" called by thread 1.
- 00:00:01.823: DllMain(0x72F90000, DLL_PROCESS_ATTACH, 0x0013FD30) in "c:\windows\system32\WINSPOOL.DRV" returned 1 (0x1) by thread 1.
- 00:00:01.863: DllMain(0x77110000, DLL_PROCESS_ATTACH, 0x0013FD30) in "c:\windows\system32\OLEAUT32.DLL" called by thread 1.
- 00:00:01.863: DllMain(0x77110000, DLL_PROCESS_ATTACH, 0x0013FD30) in "c:\windows\system32\OLEAUT32.DLL" returned 1 (0x1) by thread 1.
- 00:00:01.903: DllMain(0x77BD0000, DLL_PROCESS_ATTACH, 0x0013FD30) in "c:\windows\system32\MSACM32.DLL" called by thread 1.
- 00:00:01.903: DllMain(0x77BD0000, DLL_PROCESS_ATTACH, 0x0013FD30) in "c:\windows\system32\MSACM32.DLL" returned 1 (0x1) by thread 1.
- 00:00:01.933: DllMain(0x77BF0000, DLL_PROCESS_ATTACH, 0x0013FD30) in "c:\windows\system32\VERSION.DLL" called by thread 1.
- 00:00:01.943: DllMain(0x77BF0000, DLL_PROCESS_ATTACH, 0x0013FD30) in "c:\windows\system32\VERSION.DLL" returned 1 (0x1) by thread 1.
- 00:00:01.993: DllMain(0x5B1D0000, DLL_PROCESS_ATTACH, 0x0013FD30) in "c:\windows\system32\UXTHEME.DLL" called by thread 1.
- 00:00:01.993: DllMain(0x5B1D0000, DLL_PROCESS_ATTACH, 0x0013FD30) in "c:\windows\system32\UXTHEME.DLL" returned 1 (0x1) by thread 1.
- 00:00:02.013: LoadLibraryA("Secur32.dll") called from "c:\windows\system32\ADVAPI32.DLL" at address 0x77DD5419 by thread 1.
- 00:00:02.033: LoadLibraryA("Secur32.dll") returned 0x77FE0000 by thread 1.
- 00:00:02.083: GetProcAddress(0x77FE0000 [c:\windows\system32\SECUR32.DLL], "GetUserNameExW") called from "c:\windows\system32\ADVAPI32.DLL" at address 0x77DD546E and returned 0x77FE1C70 by thread 1.
- 00:00:02.103: LoadLibraryA("USERENV.dll") called from "c:\windows\system32\SHELL32.DLL" at address 0x7C9FFB27 by thread 1.
- 00:00:02.123: LoadLibraryA("USERENV.dll") returned 0x769A0000 by thread 1.
- 00:00:02.173: GetProcAddress(0x769A0000 [c:\windows\system32\USERENV.DLL], "GetUserProfileDirectoryW") called from "c:\windows\system32\SHELL32.DLL" at address 0x7C9FFADE and returned 0x769A6357 by thread 1.
- 00:00:02.213: GetProcAddress(0x769A0000 [c:\windows\system32\USERENV.DLL], "GetAllUsersProfileDirectoryW") called from "c:\windows\system32\SHELL32.DLL" at address 0x7C9FFADE and returned 0x769A66A1 by thread 1.
- 00:00:02.263: GetProcAddress(0x7C800000 [c:\windows\system32\KERNEL32.DLL], "IsProcessorFeaturePresent") called from "c:\windows\WELCOME.EXE" at address 0x0040766B and returned 0x7C80AEBA by thread 1.
- 00:00:02.314: DllMain(0x5D520000, DLL_PROCESS_DETACH, 0x00000001) in "c:\windows\system32\COMCTL32.DLL" called by thread 1.
- 00:00:02.334: GetProcAddress(0x7C800000 [c:\windows\system32\KERNEL32.DLL], "ReleaseActCtx") called from "c:\windows\system32\COMCTL32.DLL" at address 0x5D58F1F2 and returned 0x7C8130EF by thread 1.
- 00:00:02.354: DllMain(0x5D520000, DLL_PROCESS_DETACH, 0x00000001) in "c:\windows\system32\COMCTL32.DLL" returned 1 (0x1) by thread 1.
- 00:00:02.394: DllMain(0x773C0000, DLL_PROCESS_DETACH, 0x00000001) in "c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\COMCTL32.DLL" called by thread 1.
- 00:00:02.414: GetProcAddress(0x7C800000 [c:\windows\system32\KERNEL32.DLL], "ReleaseActCtx") called from "c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\COMCTL32.DLL" at address 0x7744B616 and returned 0x7C8130EF by thread 1.
- 00:00:02.434: DllMain(0x773C0000, DLL_PROCESS_DETACH, 0x00000001) in "c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\COMCTL32.DLL" returned 1 (0x1) by thread 1.
- 00:00:02.474: DllMain(0x59410000, DLL_PROCESS_DETACH, 0x00000001) in "c:\windows\apppatch\ACGENRAL.DLL" called by thread 1.
- 00:00:02.474: DllMain(0x59410000, DLL_PROCESS_DETACH, 0x00000001) in "c:\windows\apppatch\ACGENRAL.DLL" returned 1 (0x1) by thread 1.
- 00:00:02.514: DllMain(0x5B1D0000, DLL_PROCESS_DETACH, 0x00000001) in "c:\windows\system32\UXTHEME.DLL" called by thread 1.
- 00:00:02.514: DllMain(0x5B1D0000, DLL_PROCESS_DETACH, 0x00000001) in "c:\windows\system32\UXTHEME.DLL" returned 1 (0x1) by thread 1.
- 00:00:02.554: DllMain(0x77BF0000, DLL_PROCESS_DETACH, 0x00000001) in "c:\windows\system32\VERSION.DLL" called by thread 1.
- 00:00:02.554: DllMain(0x77BF0000, DLL_PROCESS_DETACH, 0x00000001) in "c:\windows\system32\VERSION.DLL" returned 1 (0x1) by thread 1.
- 00:00:02.584: DllMain(0x77BD0000, DLL_PROCESS_DETACH, 0x00000001) in "c:\windows\system32\MSACM32.DLL" called by thread 1.
- 00:00:02.594: DllMain(0x77BD0000, DLL_PROCESS_DETACH, 0x00000001) in "c:\windows\system32\MSACM32.DLL" returned 1 (0x1) by thread 1.
- 00:00:02.624: DllMain(0x77110000, DLL_PROCESS_DETACH, 0x00000001) in "c:\windows\system32\OLEAUT32.DLL" called by thread 1.
- 00:00:02.624: DllMain(0x77110000, DLL_PROCESS_DETACH, 0x00000001) in "c:\windows\system32\OLEAUT32.DLL" returned 1 (0x1) by thread 1.
- 00:00:02.664: DllMain(0x71620000, DLL_PROCESS_DETACH, 0x00000001) in "c:\windows\apppatch\ACLAYERS.DLL" called by thread 1.
- 00:00:02.664: DllMain(0x71620000, DLL_PROCESS_DETACH, 0x00000001) in "c:\windows\apppatch\ACLAYERS.DLL" returned 1 (0x1) by thread 1.
- 00:00:02.704: DllMain(0x72F90000, DLL_PROCESS_DETACH, 0x00000001) in "c:\windows\system32\WINSPOOL.DRV" called by thread 1.
- 00:00:02.704: DllMain(0x72F90000, DLL_PROCESS_DETACH, 0x00000001) in "c:\windows\system32\WINSPOOL.DRV" returned 1 (0x1) by thread 1.
- 00:00:02.744: DllMain(0x769A0000, DLL_PROCESS_DETACH, 0x00000001) in "c:\windows\system32\USERENV.DLL" called by thread 1.
- 00:00:02.744: DllMain(0x769A0000, DLL_PROCESS_DETACH, 0x00000001) in "c:\windows\system32\USERENV.DLL" returned 1 (0x1) by thread 1.
- 00:00:02.774: DllMain(0x774D0000, DLL_PROCESS_DETACH, 0x00000001) in "c:\windows\system32\OLE32.DLL" called by thread 1.
- 00:00:02.784: DllMain(0x774D0000, DLL_PROCESS_DETACH, 0x00000001) in "c:\windows\system32\OLE32.DLL" returned 1 (0x1) by thread 1.
- 00:00:02.824: DllMain(0x76B20000, DLL_PROCESS_DETACH, 0x00000001) in "c:\windows\system32\WINMM.DLL" called by thread 1.
- 00:00:02.824: DllMain(0x76B20000, DLL_PROCESS_DETACH, 0x00000001) in "c:\windows\system32\WINMM.DLL" returned 1 (0x1) by thread 1.
- 00:00:02.864: DllMain(0x7C9C0000, DLL_PROCESS_DETACH, 0x00000001) in "c:\windows\system32\SHELL32.DLL" called by thread 1.
- 00:00:02.884: GetProcAddress(0x7C800000 [c:\windows\system32\KERNEL32.DLL], "ReleaseActCtx") called from "c:\windows\system32\SHELL32.DLL" at address 0x7CA29F3B and returned 0x7C8130EF by thread 1.
- 00:00:02.904: DllMain(0x7C9C0000, DLL_PROCESS_DETACH, 0x00000001) in "c:\windows\system32\SHELL32.DLL" returned 1 (0x1) by thread 1.
- 00:00:02.934: DllMain(0x77F60000, DLL_PROCESS_DETACH, 0x00000001) in "c:\windows\system32\SHLWAPI.DLL" called by thread 1.
- 00:00:02.934: DllMain(0x77F60000, DLL_PROCESS_DETACH, 0x00000001) in "c:\windows\system32\SHLWAPI.DLL" returned 1 (0x1) by thread 1.
- 00:00:02.974: DllMain(0x77C00000, DLL_PROCESS_DETACH, 0x00000001) in "c:\windows\system32\MSVCRT.DLL" called by thread 1.
- 00:00:02.974: DllMain(0x77C00000, DLL_PROCESS_DETACH, 0x00000001) in "c:\windows\system32\MSVCRT.DLL" returned 1 (0x1) by thread 1.
- 00:00:03.015: DllMain(0x77DC0000, DLL_PROCESS_DETACH, 0x00000001) in "c:\windows\system32\ADVAPI32.DLL" called by thread 1.
- 00:00:03.015: DllMain(0x77DC0000, DLL_PROCESS_DETACH, 0x00000001) in "c:\windows\system32\ADVAPI32.DLL" returned 1 (0x1) by thread 1.
- 00:00:03.065: DllMain(0x77E70000, DLL_PROCESS_DETACH, 0x00000001) in "c:\windows\system32\RPCRT4.DLL" called by thread 1.
- 00:00:03.065: DllMain(0x77E70000, DLL_PROCESS_DETACH, 0x00000001) in "c:\windows\system32\RPCRT4.DLL" returned 1 (0x1) by thread 1.
- 00:00:03.095: DllMain(0x77FE0000, DLL_PROCESS_DETACH, 0x00000001) in "c:\windows\system32\SECUR32.DLL" called by thread 1.
- 00:00:03.105: DllMain(0x77FE0000, DLL_PROCESS_DETACH, 0x00000001) in "c:\windows\system32\SECUR32.DLL" returned 1 (0x1) by thread 1.
- 00:00:03.135: DllMain(0x7E360000, DLL_PROCESS_DETACH, 0x00000001) in "c:\windows\system32\USER32.DLL" called by thread 1.
- 00:00:03.135: DllMain(0x7E360000, DLL_PROCESS_DETACH, 0x00000001) in "c:\windows\system32\USER32.DLL" returned 1 (0x1) by thread 1.
- 00:00:03.175: DllMain(0x77F10000, DLL_PROCESS_DETACH, 0x00000001) in "c:\windows\system32\GDI32.DLL" called by thread 1.
- 00:00:03.175: DllMain(0x77F10000, DLL_PROCESS_DETACH, 0x00000001) in "c:\windows\system32\GDI32.DLL" returned 1 (0x1) by thread 1.
- 00:00:03.215: DllMain(0x08370000, DLL_PROCESS_DETACH, 0x00000001) in "c:\documents and settings\fluttie\pulpit\DEPENDS.DLL" called by thread 1.
- 00:00:03.235: DllMain(0x08370000, DLL_PROCESS_DETACH, 0x00000001) in "c:\documents and settings\fluttie\pulpit\DEPENDS.DLL" returned 1 (0x1) by thread 1.
- 00:00:03.275: DllMain(0x7C800000, DLL_PROCESS_DETACH, 0x00000001) in "c:\windows\system32\KERNEL32.DLL" called by thread 1.
- 00:00:03.275: DllMain(0x7C800000, DLL_PROCESS_DETACH, 0x00000001) in "c:\windows\system32\KERNEL32.DLL" returned 1 (0x1) by thread 1.
- 00:00:03.315: DllMain(0x7C900000, DLL_PROCESS_DETACH, 0x00000001) in "c:\windows\system32\NTDLL.DLL" called by thread 1.
- 00:00:03.315: DllMain(0x7C900000, DLL_PROCESS_DETACH, 0x00000001) in "c:\windows\system32\NTDLL.DLL" returned 1 (0x1) by thread 1.
- 00:00:03.335: Thread 1 exited with code 0 (0x0).
- 00:00:03.355: Thread 2 started in "c:\windows\system32\KERNEL32.DLL" at address 0x7C8106E9.
- 00:00:03.375: Exited "c:\windows\WELCOME.EXE" (process 0x7BC) with code 0 (0x0) by thread 2.
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement