Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Log data
- Address Message
- OllyDbg v2.01
- Missing SYMSRV.DLL, Microsoft Symbol Server is deactivated
- File 'C:\WINDOWS\NOTEPAD.EXE'
- New process (ID 00000D90) created
- 0100739D Main thread (ID 000005B4) created
- Debug string: AVRF: NOTEPAD.EXE: pid 0xD90: flags 0x0: application verifier enabled
- Debug string: DLL_PROCESS_VERIFIER
- Debug string: SIDE FSTATE length 0x8
- Debug string: DLL_PROCESS_VERIFIER.SEP: 0x1
- Debug string: DLL_PROCESS_VERIFIER.NtBase: 0x7C900000
- Debug string: DLL_PROCESS_VERIFIER.InitTls: 0x7C900000
- Debug string: FLT: LdrMapViewOfImage.ZwQueryVirtualMemory(): 0x0
- Debug string: FLT: LdrMapViewOfImage.FILE: \Device\HarddiskVolume1\WINDOWS\system32\ntdll.dll
- Debug string: FLT: LdrMapViewOfImage.ZwOpenFile(): 0x0
- Debug string: FLT: LdrMapViewOfImage.ZwCreateSection(): 0x0
- Debug string: FLT: LdrMapViewOfImage.ZwMapViewOfSection(): 0x40000003
- Debug string: DLL_PROCESS_VERIFIER.LdrMapViewOfImage: 0x40000003
- Debug string: DLL_PROCESS_VERIFIER.GenerateZwList: 0x0
- Debug string: DLL_PROCESS_VERIFIER.FindThreadLock: 0x7C97E20C
- Debug string: DLL_PROCESS_VERIFIER.ApiInitialize: 0x480010
- Debug string: DLL_PROCESS_VERIFIER.InitApi: 0x480010
- Debug string: DLL_INIT: 0x1
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD5CE, Id: 0x77, Name: ZwOpenKey}
- Debug string: Fret): 0x77
- Debug string: Filter(NTID{Rva: 0xD5CE, Id: 0x77, Name: ZwOpenKey}
- Debug string: Fret): 0x77
- Debug string: AVRF: verifier.dll provider initialized for NOTEPAD.EXE with flags 0x0
- Debug string: Filter(NTID{Rva: 0xD5CE, Id: 0x77, Name: ZwOpenKey}
- Debug string: Fret): 0x77
- Debug string: RouteIp(pIp: 0x6F4C0, Handler: 0x10010087, TLS_PRE: 0x7C9132F0, GetTlsFrame(): 0x10030950)
- Debug string: Filter(NTID{Rva: 0xD7FE, Id: 0x9A, Name: ZwQueryInformationProcess}
- Debug string: Filter(pZw: 0x100100F0
- Debug string: NtQueryInformationProcess(ProcessHandle: 0xFFFFFFFF, ProcessInformationClass: 0x24)
- Debug string: Fret): 0x9A
- Debug string: pRtlDecodePointer exited.
- Debug string: Rload(Ip: 0x7C9132F0, GetTlsFrame(): 0x10030974)
- Debug string: Filter(NTID{Rva: 0xD92E, Id: 0xAD, Name: ZwQuerySystemInformation}
- Debug string: Fret): 0xAD
- Debug string: Filter(NTID{Rva: 0xD92E, Id: 0xAD, Name: ZwQuerySystemInformation}
- Debug string: Fret): 0xAD
- Debug string: Filter(NTID{Rva: 0xD17E, Id: 0x32, Name: ZwCreateSection}
- Debug string: Fret): 0x32
- Debug string: Filter(NTID{Rva: 0xDB7E, Id: 0xD2, Name: ZwSecureConnectPort}
- Debug string: Fret): 0xD2
- Debug string: Filter(NTID{Rva: 0xCFEE, Id: 0x19, Name: ZwClose}
- Debug string: Filter(pZw: 0x1001006E
- Debug string: NtClose(HANDLE: 0x10, OBJECT: (null))
- Debug string: Fret): 0x19
- Debug string: Filter(NTID{Rva: 0xD88E, Id: 0xA3, Name: ZwQueryObject}
- Debug string: Fret): 0xA3
- Debug string: Filter(NTID{Rva: 0xDC8E, Id: 0xE3, Name: ZwSetInformationObject}
- Debug string: Fret): 0xE3
- Debug string: Filter(NTID{Rva: 0xD92E, Id: 0xAD, Name: ZwQuerySystemInformation}
- Debug string: Fret): 0xAD
- Debug string: Filter(NTID{Rva: 0xD97E, Id: 0xB2, Name: ZwQueryVirtualMemory}
- Debug string: Fret): 0xB2
- Debug string: Filter(NTID{Rva: 0xCF6E, Id: 0x11, Name: ZwAllocateVirtualMemory}
- Debug string: Fret): 0x11
- Debug string: Filter(NTID{Rva: 0xDADE, Id: 0xC8, Name: ZwRequestWaitReplyPort}
- Debug string: Fret): 0xC8
- Debug string: Filter(NTID{Rva: 0xDA0E, Id: 0xBB, Name: ZwRegisterThreadTerminatePort}
- Debug string: Fret): 0xBB
- Debug string: Filter(NTID{Rva: 0xD5CE, Id: 0x77, Name: ZwOpenKey}
- Debug string: Fret): 0x77
- Debug string: Filter(NTID{Rva: 0xD96E, Id: 0xB1, Name: ZwQueryValueKey}
- Debug string: Fret): 0xB1
- Debug string: Filter(NTID{Rva: 0xCFEE, Id: 0x19, Name: ZwClose}
- Debug string: Filter(pZw: 0x1001006E
- Debug string: NtClose(HANDLE: 0x10, OBJECT: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Terminal Server)
- Debug string: Fret): 0x19
- Debug string: Filter(NTID{Rva: 0xD5CE, Id: 0x77, Name: ZwOpenKey}
- Debug string: Fret): 0x77
- Debug string: Filter(NTID{Rva: 0xD96E, Id: 0xB1, Name: ZwQueryValueKey}
- Debug string: Fret): 0xB1
- Debug string: Filter(NTID{Rva: 0xCFEE, Id: 0x19, Name: ZwClose}
- Debug string: Filter(pZw: 0x1001006E
- Debug string: NtClose(HANDLE: 0x10, OBJECT: \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\notepad.exe)
- Debug string: Fret): 0x19
- Debug string: Filter(NTID{Rva: 0xD62E, Id: 0x7D, Name: ZwOpenSection}
- Debug string: Fret): 0x7D
- Debug string: Filter(NTID{Rva: 0xD92E, Id: 0xAD, Name: ZwQuerySystemInformation}
- Debug string: Fret): 0xAD
- Debug string: Filter(NTID{Rva: 0xD51E, Id: 0x6C, Name: ZwMapViewOfSection}
- Debug string: Fret): 0x6C
- Debug string: Filter(NTID{Rva: 0xCFEE, Id: 0x19, Name: ZwClose}
- Debug string: Filter(pZw: 0x1001006E
- Debug string: NtClose(HANDLE: 0x10, OBJECT: \NLS\NlsSectionUnicode)
- Debug string: Fret): 0x19
- Debug string: Filter(NTID{Rva: 0xD74E, Id: 0x8F, Name: ZwQueryDefaultLocale}
- Debug string: Fret): 0x8F
- Debug string: Filter(NTID{Rva: 0xD62E, Id: 0x7D, Name: ZwOpenSection}
- Debug string: Fret): 0x7D
- Debug string: Filter(NTID{Rva: 0xD92E, Id: 0xAD, Name: ZwQuerySystemInformation}
- Debug string: Fret): 0xAD
- Debug string: Filter(NTID{Rva: 0xD51E, Id: 0x6C, Name: ZwMapViewOfSection}
- Debug string: Fret): 0x6C
- Debug string: Filter(NTID{Rva: 0xCFEE, Id: 0x19, Name: ZwClose}
- Debug string: Filter(pZw: 0x1001006E
- Debug string: NtClose(HANDLE: 0x10, OBJECT: \NLS\NlsSectionLocale)
- Debug string: Fret): 0x19
- Debug string: Filter(NTID{Rva: 0xD62E, Id: 0x7D, Name: ZwOpenSection}
- Debug string: Fret): 0x7D
- Debug string: Filter(NTID{Rva: 0xD92E, Id: 0xAD, Name: ZwQuerySystemInformation}
- Debug string: Fret): 0xAD
- Debug string: Filter(NTID{Rva: 0xD51E, Id: 0x6C, Name: ZwMapViewOfSection}
- Debug string: Fret): 0x6C
- Debug string: Filter(NTID{Rva: 0xD8CE, Id: 0xA7, Name: ZwQuerySection}
- Debug string: Fret): 0xA7
- Debug string: Filter(NTID{Rva: 0xCFEE, Id: 0x19, Name: ZwClose}
- Debug string: Filter(pZw: 0x1001006E
- Debug string: NtClose(HANDLE: 0x10, OBJECT: \NLS\NlsSectionSortkey)
- Debug string: Fret): 0x19
- Debug string: Filter(NTID{Rva: 0xD62E, Id: 0x7D, Name: ZwOpenSection}
- Debug string: Fret): 0x7D
- Debug string: Filter(NTID{Rva: 0xD92E, Id: 0xAD, Name: ZwQuerySystemInformation}
- Debug string: Fret): 0xAD
- Debug string: Filter(NTID{Rva: 0xD51E, Id: 0x6C, Name: ZwMapViewOfSection}
- Debug string: Fret): 0x6C
- Debug string: Filter(NTID{Rva: 0xCFEE, Id: 0x19, Name: ZwClose}
- Debug string: Filter(pZw: 0x1001006E
- Debug string: NtClose(HANDLE: 0x10, OBJECT: \NLS\NlsSectionSortTbls)
- Debug string: Fret): 0x19
- Debug string: Filter(NTID{Rva: 0xD97E, Id: 0xB2, Name: ZwQueryVirtualMemory}
- Debug string: Fret): 0xB2
- Debug string: Filter(NTID{Rva: 0xD62E, Id: 0x7D, Name: ZwOpenSection}
- Debug string: Fret): 0x7D
- Debug string: Filter(NTID{Rva: 0xD62E, Id: 0x7D, Name: ZwOpenSection}
- Debug string: Fret): 0x7D
- Debug string: Filter(NTID{Rva: 0xCF6E, Id: 0x11, Name: ZwAllocateVirtualMemory}
- Debug string: Fret): 0x11
- Debug string: Filter(NTID{Rva: 0xDADE, Id: 0xC8, Name: ZwRequestWaitReplyPort}
- Debug string: Fret): 0xC8
- Debug string: Filter(NTID{Rva: 0xDADE, Id: 0xC8, Name: ZwRequestWaitReplyPort}
- Debug string: Fret): 0xC8
- Debug string: Filter(NTID{Rva: 0xD5CE, Id: 0x77, Name: ZwOpenKey}
- Debug string: Fret): 0x77
- Debug string: Filter(NTID{Rva: 0xD5CE, Id: 0x77, Name: ZwOpenKey}
- Debug string: Fret): 0x77
- Debug string: Filter(NTID{Rva: 0xD92E, Id: 0xAD, Name: ZwQuerySystemInformation}
- Debug string: Fret): 0xAD
- Debug string: Filter(NTID{Rva: 0xDADE, Id: 0xC8, Name: ZwRequestWaitReplyPort}
- Debug string: Fret): 0xC8
- Debug string: Filter(NTID{Rva: 0xD5CE, Id: 0x77, Name: ZwOpenKey}
- Debug string: Fret): 0x77
- Debug string: Filter(NTID{Rva: 0xD96E, Id: 0xB1, Name: ZwQueryValueKey}
- Debug string: Fret): 0xB1
- Debug string: Filter(NTID{Rva: 0xCFEE, Id: 0x19, Name: ZwClose}
- Debug string: Filter(pZw: 0x1001006E
- Debug string: NtClose(HANDLE: 0x10, OBJECT: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Session Manager)
- Debug string: Fret): 0x19
- Debug string: Filter(NTID{Rva: 0xCF6E, Id: 0x11, Name: ZwAllocateVirtualMemory}
- Debug string: Fret): 0x11
- Debug string: Filter(NTID{Rva: 0xD70E, Id: 0x8B, Name: ZwQueryAttributesFile}
- Debug string: Fret): 0x8B
- Debug string: Filter(NTID{Rva: 0xD59E, Id: 0x74, Name: ZwOpenFile}
- Debug string: Fret): 0x74
- Debug string: Filter(NTID{Rva: 0xD17E, Id: 0x32, Name: ZwCreateSection}
- Debug string: Fret): 0x32
- Debug string: Filter(NTID{Rva: 0xCFEE, Id: 0x19, Name: ZwClose}
- Debug string: Filter(pZw: 0x1001006E
- Debug string: NtClose(HANDLE: 0x10, OBJECT: \Device\HarddiskVolume1\WINDOWS\system32\imm32.dll)
- Debug string: Fret): 0x19
- Debug string: Filter(NTID{Rva: 0xD51E, Id: 0x6C, Name: ZwMapViewOfSection}
- Debug string: Fret): 0x6C
- Debug string: Filter(NTID{Rva: 0xCFEE, Id: 0x19, Name: ZwClose}
- Debug string: Filter(pZw: 0x1001006E
- Debug string: NtClose(HANDLE: 0x1C, OBJECT: (null))
- Debug string: Fret): 0x19
- Debug string: Filter(NTID{Rva: 0xDF0E, Id: 0x10B, Name: ZwUnmapViewOfSection}
- Debug string: Fret): 0x10B
- Debug string: Filter(NTID{Rva: 0xD70E, Id: 0x8B, Name: ZwQueryAttributesFile}
- Debug string: Fret): 0x8B
- Debug string: Filter(NTID{Rva: 0xD59E, Id: 0x74, Name: ZwOpenFile}
- Debug string: Fret): 0x74
- Debug string: Filter(NTID{Rva: 0xD17E, Id: 0x32, Name: ZwCreateSection}
- Debug string: Fret): 0x32
- Debug string: Filter(NTID{Rva: 0xCFEE, Id: 0x19, Name: ZwClose}
- Debug string: Filter(pZw: 0x1001006E
- Debug string: NtClose(HANDLE: 0x1C, OBJECT: \Device\HarddiskVolume1\WINDOWS\system32\imm32.dll)
- Debug string: Fret): 0x19
- Debug string: Filter(NTID{Rva: 0xD51E, Id: 0x6C, Name: ZwMapViewOfSection}
- Debug string: Fret): 0x6C
- Debug string: Filter(NTID{Rva: 0xCFEE, Id: 0x19, Name: ZwClose}
- Debug string: Filter(pZw: 0x1001006E
- Debug string: NtClose(HANDLE: 0x10, OBJECT: (null))
- Debug string: Fret): 0x19
- Debug string: Filter(NTID{Rva: 0xDF0E, Id: 0x10B, Name: ZwUnmapViewOfSection}
- Debug string: Fret): 0x10B
- Debug string: Filter(NTID{Rva: 0xCF6E, Id: 0x11, Name: ZwAllocateVirtualMemory}
- Debug string: Fret): 0x11
- Debug string: Filter(NTID{Rva: 0xD70E, Id: 0x8B, Name: ZwQueryAttributesFile}
- Debug string: Fret): 0x8B
- Debug string: Filter(NTID{Rva: 0xD59E, Id: 0x74, Name: ZwOpenFile}
- Debug string: Fret): 0x74
- Debug string: Filter(NTID{Rva: 0xD17E, Id: 0x32, Name: ZwCreateSection}
- Debug string: Fret): 0x32
- Debug string: Filter(NTID{Rva: 0xD8CE, Id: 0xA7, Name: ZwQuerySection}
- Debug string: Fret): 0xA7
- Debug string: Filter(NTID{Rva: 0xCFEE, Id: 0x19, Name: ZwClose}
- Debug string: Filter(pZw: 0x1001006E
- Debug string: NtClose(HANDLE: 0x10, OBJECT: \Device\HarddiskVolume1\WINDOWS\system32\imm32.dll)
- Debug string: Fret): 0x19
- Debug string: Filter(NTID{Rva: 0xD51E, Id: 0x6C, Name: ZwMapViewOfSection}
- Debug string: Fret): 0x6C
- Debug string: Filter(NTID{Rva: 0xCFEE, Id: 0x19, Name: ZwClose}
- Debug string: Filter(pZw: 0x1001006E
- Debug string: NtClose(HANDLE: 0x1C, OBJECT: (null))
- Debug string: Fret): 0x19
- Debug string: Filter(NTID{Rva: 0xD62E, Id: 0x7D, Name: ZwOpenSection}
- Debug string: Fret): 0x7D
- Debug string: Filter(NTID{Rva: 0xD51E, Id: 0x6C, Name: ZwMapViewOfSection}
- Debug string: Fret): 0x6C
- Debug string: Filter(NTID{Rva: 0xCFEE, Id: 0x19, Name: ZwClose}
- Debug string: Filter(pZw: 0x1001006E
- Debug string: NtClose(HANDLE: 0x1C, OBJECT: \KnownDlls\advapi32.dll)
- Debug string: Fret): 0x19
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD33E, Id: 0x4E, Name: ZwFlushInstructionCache}
- Debug string: Fret): 0x4E
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD33E, Id: 0x4E, Name: ZwFlushInstructionCache}
- Debug string: Fret): 0x4E
- Debug string: Filter(NTID{Rva: 0xD62E, Id: 0x7D, Name: ZwOpenSection}
- Debug string: Fret): 0x7D
- Debug string: Filter(NTID{Rva: 0xD51E, Id: 0x6C, Name: ZwMapViewOfSection}
- Debug string: Fret): 0x6C
- Debug string: Filter(NTID{Rva: 0xCFEE, Id: 0x19, Name: ZwClose}
- Debug string: Filter(pZw: 0x1001006E
- Debug string: NtClose(HANDLE: 0x1C, OBJECT: \KnownDlls\rpcrt4.dll)
- Debug string: Fret): 0x19
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD33E, Id: 0x4E, Name: ZwFlushInstructionCache}
- Debug string: Fret): 0x4E
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD33E, Id: 0x4E, Name: ZwFlushInstructionCache}
- Debug string: Fret): 0x4E
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD33E, Id: 0x4E, Name: ZwFlushInstructionCache}
- Debug string: Fret): 0x4E
- Debug string: Filter(NTID{Rva: 0xD62E, Id: 0x7D, Name: ZwOpenSection}
- Debug string: Fret): 0x7D
- Debug string: Filter(NTID{Rva: 0xD51E, Id: 0x6C, Name: ZwMapViewOfSection}
- Debug string: Fret): 0x6C
- Debug string: Filter(NTID{Rva: 0xCFEE, Id: 0x19, Name: ZwClose}
- Debug string: Filter(pZw: 0x1001006E
- Debug string: NtClose(HANDLE: 0x1C, OBJECT: \KnownDlls\Secur32.dll)
- Debug string: Fret): 0x19
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD33E, Id: 0x4E, Name: ZwFlushInstructionCache}
- Debug string: Fret): 0x4E
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD33E, Id: 0x4E, Name: ZwFlushInstructionCache}
- Debug string: Fret): 0x4E
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD33E, Id: 0x4E, Name: ZwFlushInstructionCache}
- Debug string: Fret): 0x4E
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD33E, Id: 0x4E, Name: ZwFlushInstructionCache}
- Debug string: Fret): 0x4E
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD33E, Id: 0x4E, Name: ZwFlushInstructionCache}
- Debug string: Fret): 0x4E
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD33E, Id: 0x4E, Name: ZwFlushInstructionCache}
- Debug string: Fret): 0x4E
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD33E, Id: 0x4E, Name: ZwFlushInstructionCache}
- Debug string: Fret): 0x4E
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD33E, Id: 0x4E, Name: ZwFlushInstructionCache}
- Debug string: Fret): 0x4E
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD33E, Id: 0x4E, Name: ZwFlushInstructionCache}
- Debug string: Fret): 0x4E
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD70E, Id: 0x8B, Name: ZwQueryAttributesFile}
- Debug string: Fret): 0x8B
- Debug string: Filter(NTID{Rva: 0xD5CE, Id: 0x77, Name: ZwOpenKey}
- Debug string: Fret): 0x77
- Debug string: Filter(NTID{Rva: 0xD5CE, Id: 0x77, Name: ZwOpenKey}
- Debug string: Fret): 0x77
- Debug string: Filter(NTID{Rva: 0xD96E, Id: 0xB1, Name: ZwQueryValueKey}
- Debug string: Fret): 0xB1
- Debug string: Filter(NTID{Rva: 0xCFEE, Id: 0x19, Name: ZwClose}
- Debug string: Filter(pZw: 0x1001006E
- Debug string: NtClose(HANDLE: 0x1C, OBJECT: \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize)
- Debug string: Fret): 0x19
- Debug string: Fret): 0x10F4
- Debug string: Fret): 0x1142
- Debug string: Fret): 0x101E
- Debug string: Fret): 0x10C8
- Debug string: Fret): 0x10C8
- Debug string: Fret): 0x1019
- Debug string: Fret): 0x102C
- Debug string: Fret): 0x10C8
- Debug string: Fret): 0x101E
- Debug string: Fret): 0x1101
- Debug string: Fret): 0x11B2
- Debug string: Filter(NTID{Rva: 0xD5CE, Id: 0x77, Name: ZwOpenKey}
- Debug string: Fret): 0x77
- Debug string: Filter(NTID{Rva: 0xD96E, Id: 0xB1, Name: ZwQueryValueKey}
- Debug string: Fret): 0xB1
- Debug string: Filter(NTID{Rva: 0xCFEE, Id: 0x19, Name: ZwClose}
- Debug string: Filter(pZw: 0x1001006E
- Debug string: NtClose(HANDLE: 0x28, OBJECT: \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows)
- Debug string: Fret): 0x19
- Debug string: Fret): 0x1179
- Debug string: Fret): 0x11E8
- Debug string: Fret): 0x1179
- Debug string: Fret): 0x11E8
- Debug string: Fret): 0x1179
- Debug string: Fret): 0x11E8
- Debug string: Fret): 0x1179
- Debug string: Fret): 0x11E8
- Debug string: Fret): 0x1179
- Debug string: Fret): 0x11E8
- Debug string: Fret): 0x1179
- Debug string: Fret): 0x11E8
- Debug string: Fret): 0x1179
- Debug string: Fret): 0x11E8
- Debug string: Fret): 0x1179
- Debug string: Fret): 0x11E8
- Debug string: Fret): 0x1179
- Debug string: Fret): 0x11E8
- Debug string: Fret): 0x11E8
- Debug string: Fret): 0x11E8
- Debug string: Fret): 0x11E8
- Debug string: Fret): 0x11E8
- Debug string: Fret): 0x11E8
- Debug string: Filter(NTID{Rva: 0xCF9E, Id: 0x14, Name: ZwCallbackReturn}
- Debug string: Fret): 0x14
- Debug string: Fret): 0x10DC
- Debug string: Fret): 0x10C8
- Debug string: Fret): 0x10C8
- Debug string: Fret): 0x11E3
- Debug string: Fret): 0x11E3
- Debug string: Filter(NTID{Rva: 0xD5CE, Id: 0x77, Name: ZwOpenKey}
- Debug string: Fret): 0x77
- Debug string: DLL_INIT: 0x1
- Debug string: Filter(NTID{Rva: 0xD5CE, Id: 0x77, Name: ZwOpenKey}
- Debug string: Fret): 0x77
- Debug string: Filter(NTID{Rva: 0xD18E, Id: 0x33, Name: ZwCreateSemaphore}
- Debug string: Fret): 0x33
- Debug string: Filter(NTID{Rva: 0xD18E, Id: 0x33, Name: ZwCreateSemaphore}
- Debug string: Fret): 0x33
- Debug string: Filter(NTID{Rva: 0xD5CE, Id: 0x77, Name: ZwOpenKey}
- Debug string: Fret): 0x77
- Debug string: Filter(NTID{Rva: 0xCF6E, Id: 0x11, Name: ZwAllocateVirtualMemory}
- Debug string: Fret): 0x11
- Debug string: Filter(NTID{Rva: 0xD5CE, Id: 0x77, Name: ZwOpenKey}
- Debug string: Fret): 0x77
- Debug string: Filter(NTID{Rva: 0xD5CE, Id: 0x77, Name: ZwOpenKey}
- Debug string: Fret): 0x77
- Debug string: Filter(NTID{Rva: 0xD96E, Id: 0xB1, Name: ZwQueryValueKey}
- Debug string: Fret): 0xB1
- Debug string: Filter(NTID{Rva: 0xCFEE, Id: 0x19, Name: ZwClose}
- Debug string: Filter(pZw: 0x1001006E
- Debug string: NtClose(HANDLE: 0x30, OBJECT: \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon)
- Debug string: Fret): 0x19
- Debug string: Filter(NTID{Rva: 0xD5CE, Id: 0x77, Name: ZwOpenKey}
- Debug string: Fret): 0x77
- Debug string: Filter(NTID{Rva: 0xDC8E, Id: 0xE3, Name: ZwSetInformationObject}
- Debug string: Fret): 0xE3
- Debug string: Filter(NTID{Rva: 0xD5CE, Id: 0x77, Name: ZwOpenKey}
- Debug string: Fret): 0x77
- Debug string: Filter(NTID{Rva: 0xD5CE, Id: 0x77, Name: ZwOpenKey}
- Debug string: Fret): 0x77
- Debug string: Filter(NTID{Rva: 0xD92E, Id: 0xAD, Name: ZwQuerySystemInformation}
- Debug string: Fret): 0xAD
- Debug string: Filter(NTID{Rva: 0xD62E, Id: 0x7D, Name: ZwOpenSection}
- Debug string: Fret): 0x7D
- Debug string: Filter(NTID{Rva: 0xD51E, Id: 0x6C, Name: ZwMapViewOfSection}
- Debug string: Fret): 0x6C
- Debug string: Filter(NTID{Rva: 0xCFEE, Id: 0x19, Name: ZwClose}
- Debug string: Filter(pZw: 0x1001006E
- Debug string: NtClose(HANDLE: 0x34, OBJECT: \KnownDlls\comdlg32.dll)
- Debug string: Fret): 0x19
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD33E, Id: 0x4E, Name: ZwFlushInstructionCache}
- Debug string: Fret): 0x4E
- Debug string: Filter(NTID{Rva: 0xD5CE, Id: 0x77, Name: ZwOpenKey}
- Debug string: Fret): 0x77
- Debug string: Filter(NTID{Rva: 0xD73E, Id: 0x8E, Name: ZwQueryDebugFilterState}
- Debug string: Fret): 0x8E
- Debug string: Filter(NTID{Rva: 0xD73E, Id: 0x8E, Name: ZwQueryDebugFilterState}
- Debug string: Fret): 0x8E
- Debug string: Filter(NTID{Rva: 0xD70E, Id: 0x8B, Name: ZwQueryAttributesFile}
- Debug string: Fret): 0x8B
- Debug string: Filter(NTID{Rva: 0xD73E, Id: 0x8E, Name: ZwQueryDebugFilterState}
- Debug string: Fret): 0x8E
- Debug string: Filter(NTID{Rva: 0xD73E, Id: 0x8E, Name: ZwQueryDebugFilterState}
- Debug string: Fret): 0x8E
- Debug string: Filter(NTID{Rva: 0xD73E, Id: 0x8E, Name: ZwQueryDebugFilterState}
- Debug string: Fret): 0x8E
- Debug string: Filter(NTID{Rva: 0xD70E, Id: 0x8B, Name: ZwQueryAttributesFile}
- Debug string: Fret): 0x8B
- Debug string: Filter(NTID{Rva: 0xD59E, Id: 0x74, Name: ZwOpenFile}
- Debug string: Fret): 0x74
- Debug string: Filter(NTID{Rva: 0xD73E, Id: 0x8E, Name: ZwQueryDebugFilterState}
- Debug string: Fret): 0x8E
- Debug string: Filter(NTID{Rva: 0xD59E, Id: 0x74, Name: ZwOpenFile}
- Debug string: Fret): 0x74
- Debug string: Filter(NTID{Rva: 0xD17E, Id: 0x32, Name: ZwCreateSection}
- Debug string: Fret): 0x32
- Debug string: Filter(NTID{Rva: 0xD8CE, Id: 0xA7, Name: ZwQuerySection}
- Debug string: Fret): 0xA7
- Debug string: Filter(NTID{Rva: 0xCFEE, Id: 0x19, Name: ZwClose}
- Debug string: Filter(pZw: 0x1001006E
- Debug string: NtClose(HANDLE: 0x38, OBJECT: \Device\HarddiskVolume1\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll)
- Debug string: Fret): 0x19
- Debug string: Filter(NTID{Rva: 0xD51E, Id: 0x6C, Name: ZwMapViewOfSection}
- Debug string: Fret): 0x6C
- Debug string: Filter(NTID{Rva: 0xCFEE, Id: 0x19, Name: ZwClose}
- Debug string: Filter(pZw: 0x1001006E
- Debug string: NtClose(HANDLE: 0x3C, OBJECT: (null))
- Debug string: Fret): 0x19
- Debug string: Filter(NTID{Rva: 0xD62E, Id: 0x7D, Name: ZwOpenSection}
- Debug string: Fret): 0x7D
- Debug string: Filter(NTID{Rva: 0xD51E, Id: 0x6C, Name: ZwMapViewOfSection}
- Debug string: Fret): 0x6C
- Debug string: Filter(NTID{Rva: 0xCFEE, Id: 0x19, Name: ZwClose}
- Debug string: Filter(pZw: 0x1001006E
- Debug string: NtClose(HANDLE: 0x3C, OBJECT: \KnownDlls\msvcrt.dll)
- Debug string: Fret): 0x19
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD33E, Id: 0x4E, Name: ZwFlushInstructionCache}
- Debug string: Fret): 0x4E
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD33E, Id: 0x4E, Name: ZwFlushInstructionCache}
- Debug string: Fret): 0x4E
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD33E, Id: 0x4E, Name: ZwFlushInstructionCache}
- Debug string: Fret): 0x4E
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD33E, Id: 0x4E, Name: ZwFlushInstructionCache}
- Debug string: Fret): 0x4E
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD33E, Id: 0x4E, Name: ZwFlushInstructionCache}
- Debug string: Fret): 0x4E
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD33E, Id: 0x4E, Name: ZwFlushInstructionCache}
- Debug string: Fret): 0x4E
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD33E, Id: 0x4E, Name: ZwFlushInstructionCache}
- Debug string: Fret): 0x4E
- Debug string: Filter(NTID{Rva: 0xD62E, Id: 0x7D, Name: ZwOpenSection}
- Debug string: Fret): 0x7D
- Debug string: Filter(NTID{Rva: 0xD51E, Id: 0x6C, Name: ZwMapViewOfSection}
- Debug string: Fret): 0x6C
- Debug string: Filter(NTID{Rva: 0xCFEE, Id: 0x19, Name: ZwClose}
- Debug string: Filter(pZw: 0x1001006E
- Debug string: NtClose(HANDLE: 0x3C, OBJECT: \KnownDlls\SHLWAPI.dll)
- Debug string: Fret): 0x19
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD33E, Id: 0x4E, Name: ZwFlushInstructionCache}
- Debug string: Fret): 0x4E
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD33E, Id: 0x4E, Name: ZwFlushInstructionCache}
- Debug string: Fret): 0x4E
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD33E, Id: 0x4E, Name: ZwFlushInstructionCache}
- Debug string: Fret): 0x4E
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD33E, Id: 0x4E, Name: ZwFlushInstructionCache}
- Debug string: Fret): 0x4E
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD33E, Id: 0x4E, Name: ZwFlushInstructionCache}
- Debug string: Fret): 0x4E
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD33E, Id: 0x4E, Name: ZwFlushInstructionCache}
- Debug string: Fret): 0x4E
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD33E, Id: 0x4E, Name: ZwFlushInstructionCache}
- Debug string: Fret): 0x4E
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD33E, Id: 0x4E, Name: ZwFlushInstructionCache}
- Debug string: Fret): 0x4E
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD33E, Id: 0x4E, Name: ZwFlushInstructionCache}
- Debug string: Fret): 0x4E
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD33E, Id: 0x4E, Name: ZwFlushInstructionCache}
- Debug string: Fret): 0x4E
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD33E, Id: 0x4E, Name: ZwFlushInstructionCache}
- Debug string: Fret): 0x4E
- Debug string: Filter(NTID{Rva: 0xD62E, Id: 0x7D, Name: ZwOpenSection}
- Debug string: Fret): 0x7D
- Debug string: Filter(NTID{Rva: 0xD51E, Id: 0x6C, Name: ZwMapViewOfSection}
- Debug string: Fret): 0x6C
- Debug string: Filter(NTID{Rva: 0xCFEE, Id: 0x19, Name: ZwClose}
- Debug string: Filter(pZw: 0x1001006E
- Debug string: NtClose(HANDLE: 0x3C, OBJECT: \KnownDlls\shell32.dll)
- Debug string: Fret): 0x19
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD33E, Id: 0x4E, Name: ZwFlushInstructionCache}
- Debug string: Fret): 0x4E
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD33E, Id: 0x4E, Name: ZwFlushInstructionCache}
- Debug string: Fret): 0x4E
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD33E, Id: 0x4E, Name: ZwFlushInstructionCache}
- Debug string: Fret): 0x4E
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD33E, Id: 0x4E, Name: ZwFlushInstructionCache}
- Debug string: Fret): 0x4E
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD33E, Id: 0x4E, Name: ZwFlushInstructionCache}
- Debug string: Fret): 0x4E
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD33E, Id: 0x4E, Name: ZwFlushInstructionCache}
- Debug string: Fret): 0x4E
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD33E, Id: 0x4E, Name: ZwFlushInstructionCache}
- Debug string: Fret): 0x4E
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD33E, Id: 0x4E, Name: ZwFlushInstructionCache}
- Debug string: Fret): 0x4E
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD33E, Id: 0x4E, Name: ZwFlushInstructionCache}
- Debug string: Fret): 0x4E
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD33E, Id: 0x4E, Name: ZwFlushInstructionCache}
- Debug string: Fret): 0x4E
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD33E, Id: 0x4E, Name: ZwFlushInstructionCache}
- Debug string: Fret): 0x4E
- Debug string: Filter(NTID{Rva: 0xCF6E, Id: 0x11, Name: ZwAllocateVirtualMemory}
- Debug string: Fret): 0x11
- Debug string: Filter(NTID{Rva: 0xD62E, Id: 0x7D, Name: ZwOpenSection}
- Debug string: Fret): 0x7D
- Debug string: Filter(NTID{Rva: 0xCF6E, Id: 0x11, Name: ZwAllocateVirtualMemory}
- Debug string: Fret): 0x11
- Debug string: Filter(NTID{Rva: 0xD70E, Id: 0x8B, Name: ZwQueryAttributesFile}
- Debug string: Fret): 0x8B
- Debug string: Filter(NTID{Rva: 0xD70E, Id: 0x8B, Name: ZwQueryAttributesFile}
- Debug string: Fret): 0x8B
- Debug string: Filter(NTID{Rva: 0xD59E, Id: 0x74, Name: ZwOpenFile}
- Debug string: Fret): 0x74
- Debug string: Filter(NTID{Rva: 0xD17E, Id: 0x32, Name: ZwCreateSection}
- Debug string: Fret): 0x32
- Debug string: Filter(NTID{Rva: 0xD8CE, Id: 0xA7, Name: ZwQuerySection}
- Debug string: Fret): 0xA7
- Debug string: Filter(NTID{Rva: 0xCFEE, Id: 0x19, Name: ZwClose}
- Debug string: Filter(pZw: 0x1001006E
- Debug string: NtClose(HANDLE: 0x3C, OBJECT: \Device\HarddiskVolume1\WINDOWS\system32\winspool.drv)
- Debug string: Fret): 0x19
- Debug string: Filter(NTID{Rva: 0xD51E, Id: 0x6C, Name: ZwMapViewOfSection}
- Debug string: Fret): 0x6C
- Debug string: Filter(NTID{Rva: 0xCFEE, Id: 0x19, Name: ZwClose}
- Debug string: Filter(pZw: 0x1001006E
- Debug string: NtClose(HANDLE: 0x38, OBJECT: (null))
- Debug string: Fret): 0x19
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD33E, Id: 0x4E, Name: ZwFlushInstructionCache}
- Debug string: Fret): 0x4E
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD33E, Id: 0x4E, Name: ZwFlushInstructionCache}
- Debug string: Fret): 0x4E
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD33E, Id: 0x4E, Name: ZwFlushInstructionCache}
- Debug string: Fret): 0x4E
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD33E, Id: 0x4E, Name: ZwFlushInstructionCache}
- Debug string: Fret): 0x4E
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD33E, Id: 0x4E, Name: ZwFlushInstructionCache}
- Debug string: Fret): 0x4E
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD33E, Id: 0x4E, Name: ZwFlushInstructionCache}
- Debug string: Fret): 0x4E
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD33E, Id: 0x4E, Name: ZwFlushInstructionCache}
- Debug string: Fret): 0x4E
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD33E, Id: 0x4E, Name: ZwFlushInstructionCache}
- Debug string: Fret): 0x4E
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD33E, Id: 0x4E, Name: ZwFlushInstructionCache}
- Debug string: Fret): 0x4E
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD33E, Id: 0x4E, Name: ZwFlushInstructionCache}
- Debug string: Fret): 0x4E
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD33E, Id: 0x4E, Name: ZwFlushInstructionCache}
- Debug string: Fret): 0x4E
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- 003B0000 Module <Mod_003B> (anonymous)
- 01000000 Module 'C:\WINDOWS\NOTEPAD.EXE'
- PDB file: 'C:\WINDOWS\symbols\EXE\notepad.pdb'
- 10000000 Module 'C:\WINDOWS\System32\Flt.dll'
- PDB file: 'E:\Nt\_icplib\______________LV\Arachne\Filter\Model\Flt.pdb'
- 5B1F0000 Module 'C:\WINDOWS\System32\verifier.dll'
- PDB file: 'C:\WINDOWS\symbols\dll\verifier.pdb'
- 72FC0000 Module 'C:\WINDOWS\system32\WINSPOOL.DRV'
- PDB file: 'C:\WINDOWS\symbols\DRV\winspool.pdb'
- 76360000 Module 'C:\WINDOWS\system32\IMM32.DLL'
- PDB file: 'C:\WINDOWS\symbols\DLL\imm32.pdb'
- 76380000 Module 'C:\WINDOWS\system32\comdlg32.dll'
- PDB file: 'C:\WINDOWS\symbols\dll\comdlg32.pdb'
- 773C0000 Module 'C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\COMCTL32.dll'
- 77C00000 Module 'C:\WINDOWS\system32\msvcrt.dll'
- PDB file: 'C:\WINDOWS\symbols\dll\msvcrt.pdb'
- 77DC0000 Module 'C:\WINDOWS\system32\ADVAPI32.dll'
- 77E70000 Module 'C:\WINDOWS\system32\RPCRT4.dll'
- Code sections '.text' and '.orpc' will be merged to a single memory block
- 77F10000 Module 'C:\WINDOWS\system32\GDI32.dll'
- 77F60000 Module 'C:\WINDOWS\system32\SHLWAPI.dll'
- 77FE0000 Module 'C:\WINDOWS\system32\Secur32.dll'
- 7C800000 Module 'C:\WINDOWS\system32\KERNEL32.dll'
- 7C900000 Module 'C:\WINDOWS\system32\ntdll.dll'
- PDB file: 'C:\Symbols\ntdll.pdb\CEFC0863B1F84130A11E0F54180CD21A2\ntdll.pdb'
- 7C9C0000 Module 'C:\WINDOWS\system32\SHELL32.dll'
- 7E360000 Module 'C:\WINDOWS\system32\USER32.dll'
- PDB file: 'C:\WINDOWS\symbols\dll\user32.pdb'
- Debug string: Filter(NTID{Rva: 0xDC9E, Id: 0xE4, Name: ZwSetInformationProcess}
- Debug string: Filter(pZw: 0x100100EB
- Debug string: NtSetInformationProcess(ProcessHandle: 0xFFFFFFFF, ProcessInformationClass: 0x22)
- Debug string: Fret): 0xE4
- Debug string: Filter(NTID{Rva: 0xD5CE, Id: 0x77, Name: ZwOpenKey}
- Debug string: Fret): 0x77
- Debug string: Filter(NTID{Rva: 0xD96E, Id: 0xB1, Name: ZwQueryValueKey}
- Debug string: Fret): 0xB1
- Debug string: Filter(NTID{Rva: 0xCFEE, Id: 0x19, Name: ZwClose}
- Debug string: Filter(pZw: 0x1001006E
- Debug string: NtClose(HANDLE: 0x38, OBJECT: \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\notepad.exe)
- Debug string: Fret): 0x19
- Debug string: Filter(NTID{Rva: 0xD5CE, Id: 0x77, Name: ZwOpenKey}
- Debug string: Fret): 0x77
- Debug string: Filter(NTID{Rva: 0xD96E, Id: 0xB1, Name: ZwQueryValueKey}
- Debug string: Fret): 0xB1
- Debug string: Filter(NTID{Rva: 0xCFEE, Id: 0x19, Name: ZwClose}
- Debug string: Filter(pZw: 0x1001006E
- Debug string: NtClose(HANDLE: 0x38, OBJECT: \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\notepad.exe)
- Debug string: Fret): 0x19
- Debug string: Filter(NTID{Rva: 0xD75E, Id: 0x90, Name: ZwQueryDefaultUILanguage}
- Debug string: Fret): 0x90
- Debug string: Filter(NTID{Rva: 0xD74E, Id: 0x8F, Name: ZwQueryDefaultLocale}
- Debug string: Fret): 0x8F
- Debug string: Filter(NTID{Rva: 0xD7FE, Id: 0x9A, Name: ZwQueryInformationProcess}
- Debug string: Filter(pZw: 0x100100F0
- Debug string: NtQueryInformationProcess(ProcessHandle: 0xFFFFFFFF, ProcessInformationClass: 0x25)
- Debug string: Fret): 0x9A
- Debug string: Filter(NTID{Rva: 0xD5CE, Id: 0x77, Name: ZwOpenKey}
- Debug string: Fret): 0x77
- Debug string: Filter(NTID{Rva: 0xD5CE, Id: 0x77, Name: ZwOpenKey}
- Debug string: Fret): 0x77
- Debug string: Filter(NTID{Rva: 0xD92E, Id: 0xAD, Name: ZwQuerySystemInformation}
- Debug string: Fret): 0xAD
- Debug string: Filter(NTID{Rva: 0xCF6E, Id: 0x11, Name: ZwAllocateVirtualMemory}
- Debug string: Fret): 0x11
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD8AE, Id: 0xA5, Name: ZwQueryPerformanceCounter}
- Debug string: Fret): 0xA5
- Debug string: Filter(NTID{Rva: 0xD92E, Id: 0xAD, Name: ZwQuerySystemInformation}
- Debug string: Fret): 0xAD
- Debug string: Filter(NTID{Rva: 0xCF6E, Id: 0x11, Name: ZwAllocateVirtualMemory}
- Debug string: Fret): 0x11
- Debug string: Filter(NTID{Rva: 0xCF6E, Id: 0x11, Name: ZwAllocateVirtualMemory}
- Debug string: Fret): 0x11
- Debug string: Filter(NTID{Rva: 0xCF6E, Id: 0x11, Name: ZwAllocateVirtualMemory}
- Debug string: Fret): 0x11
- Debug string: Filter(NTID{Rva: 0xCF6E, Id: 0x11, Name: ZwAllocateVirtualMemory}
- Debug string: Fret): 0x11
- Debug string: Filter(NTID{Rva: 0xD62E, Id: 0x7D, Name: ZwOpenSection}
- Debug string: Fret): 0x7D
- Debug string: Filter(NTID{Rva: 0xD92E, Id: 0xAD, Name: ZwQuerySystemInformation}
- Debug string: Fret): 0xAD
- Debug string: Filter(NTID{Rva: 0xD51E, Id: 0x6C, Name: ZwMapViewOfSection}
- Debug string: Fret): 0x6C
- Debug string: Filter(NTID{Rva: 0xCFEE, Id: 0x19, Name: ZwClose}
- Debug string: Filter(pZw: 0x1001006E
- Debug string: NtClose(HANDLE: 0x38, OBJECT: \NLS\NlsSectionCType)
- Debug string: Fret): 0x19
- Debug string: Filter(NTID{Rva: 0xCF6E, Id: 0x11, Name: ZwAllocateVirtualMemory}
- Debug string: Fret): 0x11
- Debug string: Filter(NTID{Rva: 0xCF6E, Id: 0x11, Name: ZwAllocateVirtualMemory}
- Debug string: Fret): 0x11
- Debug string: Filter(NTID{Rva: 0xD97E, Id: 0xB2, Name: ZwQueryVirtualMemory}
- Debug string: Fret): 0xB2
- Debug string: RouteIp(pIp: 0x6F6E8, Handler: 0x10010087, TLS_PRE: 0x7C9132F0, GetTlsFrame(): 0x10030950)
- Debug string: Filter(NTID{Rva: 0xD7FE, Id: 0x9A, Name: ZwQueryInformationProcess}
- Debug string: Filter(pZw: 0x100100F0
- Debug string: NtQueryInformationProcess(ProcessHandle: 0xFFFFFFFF, ProcessInformationClass: 0x24)
- Debug string: Fret): 0x9A
- Debug string: pRtlDecodePointer exited.
- Debug string: Rload(Ip: 0x7C9132F0, GetTlsFrame(): 0x10030974)
- Debug string: RouteIp(pIp: 0x6F6E8, Handler: 0x10010087, TLS_PRE: 0x7C9132F0, GetTlsFrame(): 0x10030950)
- Debug string: Filter(NTID{Rva: 0xD7FE, Id: 0x9A, Name: ZwQueryInformationProcess}
- Debug string: Filter(pZw: 0x100100F0
- Debug string: NtQueryInformationProcess(ProcessHandle: 0xFFFFFFFF, ProcessInformationClass: 0x24)
- Debug string: Fret): 0x9A
- Debug string: pRtlDecodePointer exited.
- Debug string: Rload(Ip: 0x7C9132F0, GetTlsFrame(): 0x10030974)
- Debug string: Filter(NTID{Rva: 0xD97E, Id: 0xB2, Name: ZwQueryVirtualMemory}
- Debug string: Fret): 0xB2
- Debug string: Filter(NTID{Rva: 0xD5CE, Id: 0x77, Name: ZwOpenKey}
- Debug string: Fret): 0x77
- Debug string: Filter(NTID{Rva: 0xD5CE, Id: 0x77, Name: ZwOpenKey}
- Debug string: Fret): 0x77
- Debug string: Filter(NTID{Rva: 0xD5CE, Id: 0x77, Name: ZwOpenKey}
- Debug string: Fret): 0x77
- Debug string: Filter(NTID{Rva: 0xCF6E, Id: 0x11, Name: ZwAllocateVirtualMemory}
- Debug string: Fret): 0x11
- Debug string: Filter(NTID{Rva: 0xD56E, Id: 0x71, Name: ZwOpenDirectoryObject}
- Debug string: Fret): 0x71
- Debug string: Filter(NTID{Rva: 0xD18E, Id: 0x33, Name: ZwCreateSemaphore}
- Debug string: Fret): 0x33
- Debug string: Filter(NTID{Rva: 0xD5CE, Id: 0x77, Name: ZwOpenKey}
- Debug string: Fret): 0x77
- Debug string: Filter(NTID{Rva: 0xD5CE, Id: 0x77, Name: ZwOpenKey}
- Debug string: Fret): 0x77
- Debug string: Filter(NTID{Rva: 0xCEDE, Id: 0x8, Name: ZwAddAtom}
- Debug string: Fret): 0x8
- Debug string: Filter(NTID{Rva: 0xD75E, Id: 0x90, Name: ZwQueryDefaultUILanguage}
- Debug string: Fret): 0x90
- Debug string: Filter(NTID{Rva: 0xD70E, Id: 0x8B, Name: ZwQueryAttributesFile}
- Debug string: Fret): 0x8B
- Debug string: Filter(NTID{Rva: 0xCF6E, Id: 0x11, Name: ZwAllocateVirtualMemory}
- Debug string: Fret): 0x11
- Debug string: Filter(NTID{Rva: 0xD59E, Id: 0x74, Name: ZwOpenFile}
- Debug string: Fret): 0x74
- Debug string: Filter(NTID{Rva: 0xD17E, Id: 0x32, Name: ZwCreateSection}
- Debug string: Fret): 0x32
- Debug string: Filter(NTID{Rva: 0xCFEE, Id: 0x19, Name: ZwClose}
- Debug string: Filter(pZw: 0x1001006E
- Debug string: NtClose(HANDLE: 0x40, OBJECT: \Device\HarddiskVolume1\WINDOWS\WindowsShell.Manifest)
- Debug string: Fret): 0x19
- Debug string: Filter(NTID{Rva: 0xD51E, Id: 0x6C, Name: ZwMapViewOfSection}
- Debug string: Fret): 0x6C
- Debug string: Filter(NTID{Rva: 0xCFEE, Id: 0x19, Name: ZwClose}
- Debug string: Filter(pZw: 0x1001006E
- Debug string: NtClose(HANDLE: 0x44, OBJECT: (null))
- Debug string: Fret): 0x19
- Debug string: Filter(NTID{Rva: 0xDF0E, Id: 0x10B, Name: ZwUnmapViewOfSection}
- Debug string: Fret): 0x10B
- Debug string: Filter(NTID{Rva: 0xD70E, Id: 0x8B, Name: ZwQueryAttributesFile}
- Debug string: Fret): 0x8B
- Debug string: Filter(NTID{Rva: 0xD0AE, Id: 0x25, Name: ZwCreateFile}
- Debug string: Fret): 0x25
- Debug string: Filter(NTID{Rva: 0xD17E, Id: 0x32, Name: ZwCreateSection}
- Debug string: Fret): 0x32
- Debug string: Filter(NTID{Rva: 0xCFEE, Id: 0x19, Name: ZwClose}
- Debug string: Filter(pZw: 0x1001006E
- Debug string: NtClose(HANDLE: 0x44, OBJECT: \Device\HarddiskVolume1\WINDOWS\WindowsShell.Manifest)
- Debug string: Fret): 0x19
- Debug string: Filter(NTID{Rva: 0xD92E, Id: 0xAD, Name: ZwQuerySystemInformation}
- Debug string: Fret): 0xAD
- Debug string: Filter(NTID{Rva: 0xD51E, Id: 0x6C, Name: ZwMapViewOfSection}
- Debug string: Fret): 0x6C
- Debug string: Filter(NTID{Rva: 0xCFEE, Id: 0x19, Name: ZwClose}
- Debug string: Filter(pZw: 0x1001006E
- Debug string: NtClose(HANDLE: 0x40, OBJECT: (null))
- Debug string: Fret): 0x19
- Debug string: Filter(NTID{Rva: 0xDF0E, Id: 0x10B, Name: ZwUnmapViewOfSection}
- Debug string: Fret): 0x10B
- Debug string: Filter(NTID{Rva: 0xD59E, Id: 0x74, Name: ZwOpenFile}
- Debug string: Fret): 0x74
- Debug string: Filter(NTID{Rva: 0xD17E, Id: 0x32, Name: ZwCreateSection}
- Debug string: Fret): 0x32
- Debug string: Filter(NTID{Rva: 0xD92E, Id: 0xAD, Name: ZwQuerySystemInformation}
- Debug string: Fret): 0xAD
- Debug string: Filter(NTID{Rva: 0xD51E, Id: 0x6C, Name: ZwMapViewOfSection}
- Debug string: Fret): 0x6C
- Debug string: Filter(NTID{Rva: 0xD7CE, Id: 0x97, Name: ZwQueryInformationFile}
- Debug string: Fret): 0x97
- Debug string: Filter(NTID{Rva: 0xD59E, Id: 0x74, Name: ZwOpenFile}
- Debug string: Fret): 0x74
- Debug string: Filter(NTID{Rva: 0xDADE, Id: 0xC8, Name: ZwRequestWaitReplyPort}
- Debug string: Fret): 0xC8
- Debug string: Filter(NTID{Rva: 0xCFEE, Id: 0x19, Name: ZwClose}
- Debug string: Filter(pZw: 0x1001006E
- Debug string: NtClose(HANDLE: 0x40, OBJECT: \Device\HarddiskVolume1\WINDOWS\WindowsShell.Manifest)
- Debug string: Fret): 0x19
- Debug string: Filter(NTID{Rva: 0xCFEE, Id: 0x19, Name: ZwClose}
- Debug string: Filter(pZw: 0x1001006E
- Debug string: NtClose(HANDLE: 0x44, OBJECT: (null))
- Debug string: Fret): 0x19
- Debug string: Filter(NTID{Rva: 0xDF0E, Id: 0x10B, Name: ZwUnmapViewOfSection}
- Debug string: Fret): 0x10B
- Debug string: Filter(NTID{Rva: 0xD73E, Id: 0x8E, Name: ZwQueryDebugFilterState}
- Debug string: Fret): 0x8E
- Debug string: Fret): 0x11ED
- Debug string: Fret): 0x122F
- Debug string: Fret): 0x1191
- Debug string: Fret): 0x1143
- Debug string: Fret): 0x122F
- Debug string: Fret): 0x122F
- Debug string: Filter(NTID{Rva: 0xD67E, Id: 0x82, Name: ZwOpenThreadTokenEx}
- Debug string: Fret): 0x82
- Debug string: Filter(NTID{Rva: 0xD61E, Id: 0x7C, Name: ZwOpenProcessTokenEx}
- Debug string: Fret): 0x7C
- Debug string: Filter(NTID{Rva: 0xD81E, Id: 0x9C, Name: ZwQueryInformationToken}
- Debug string: Fret): 0x9C
- Debug string: Filter(NTID{Rva: 0xCFEE, Id: 0x19, Name: ZwClose}
- Debug string: Filter(pZw: 0x1001006E
- Debug string: NtClose(HANDLE: 0x44, OBJECT: (null))
- Debug string: Fret): 0x19
- Debug string: Filter(NTID{Rva: 0xD5CE, Id: 0x77, Name: ZwOpenKey}
- Debug string: Fret): 0x77
- Debug string: Filter(NTID{Rva: 0xD60E, Id: 0x7B, Name: ZwOpenProcessToken}
- Debug string: Fret): 0x7B
- Debug string: Filter(NTID{Rva: 0xCE6E, Id: 0x1, Name: ZwAccessCheck}
- Debug string: Fret): 0x1
- Debug string: Filter(NTID{Rva: 0xCFEE, Id: 0x19, Name: ZwClose}
- Debug string: Filter(pZw: 0x1001006E
- Debug string: NtClose(HANDLE: 0x40, OBJECT: (null))
- Debug string: Fret): 0x19
- Debug string: Filter(NTID{Rva: 0xD5CE, Id: 0x77, Name: ZwOpenKey}
- Debug string: Fret): 0x77
- Debug string: Filter(NTID{Rva: 0xD96E, Id: 0xB1, Name: ZwQueryValueKey}
- Debug string: Fret): 0xB1
- Debug string: Filter(NTID{Rva: 0xCFEE, Id: 0x19, Name: ZwClose}
- Debug string: Filter(pZw: 0x1001006E
- Debug string: NtClose(HANDLE: 0x40, OBJECT: \REGISTRY\USER\S-1-5-21-299502267-1972579041-1275210071-1003\Control Panel\Desktop)
- Debug string: Fret): 0x19
- Debug string: Fret): 0x122F
- Debug string: Filter(NTID{Rva: 0xD60E, Id: 0x7B, Name: ZwOpenProcessToken}
- Debug string: Fret): 0x7B
- Debug string: Filter(NTID{Rva: 0xCE6E, Id: 0x1, Name: ZwAccessCheck}
- Debug string: Fret): 0x1
- Debug string: Filter(NTID{Rva: 0xCFEE, Id: 0x19, Name: ZwClose}
- Debug string: Filter(pZw: 0x1001006E
- Debug string: NtClose(HANDLE: 0x40, OBJECT: (null))
- Debug string: Fret): 0x19
- Debug string: Filter(NTID{Rva: 0xD5CE, Id: 0x77, Name: ZwOpenKey}
- Debug string: Fret): 0x77
- Debug string: Filter(NTID{Rva: 0xD96E, Id: 0xB1, Name: ZwQueryValueKey}
- Debug string: Fret): 0xB1
- Debug string: Filter(NTID{Rva: 0xCFEE, Id: 0x19, Name: ZwClose}
- Debug string: Filter(pZw: 0x1001006E
- Debug string: NtClose(HANDLE: 0x40, OBJECT: \REGISTRY\USER\S-1-5-21-299502267-1972579041-1275210071-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced)
- Debug string: Fret): 0x19
- Debug string: Fret): 0x122F
- Debug string: Fret): 0x122F
- Debug string: Filter(NTID{Rva: 0xCFEE, Id: 0x19, Name: ZwClose}
- Debug string: Filter(pZw: 0x1001006E
- Debug string: NtClose(HANDLE: 0x44, OBJECT: \REGISTRY\USER\S-1-5-21-299502267-1972579041-1275210071-1003)
- Debug string: Fret): 0x19
- Debug string: Fret): 0x122F
- Debug string: Filter(NTID{Rva: 0xD5CE, Id: 0x77, Name: ZwOpenKey}
- Debug string: Fret): 0x77
- Debug string: Filter(NTID{Rva: 0xD2EE, Id: 0x49, Name: ZwEnumerateValueKey}
- Debug string: Fret): 0x49
- Debug string: Filter(NTID{Rva: 0xCFEE, Id: 0x19, Name: ZwClose}
- Debug string: Filter(pZw: 0x1001006E
- Debug string: NtClose(HANDLE: 0x44, OBJECT: \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack)
- Debug string: Fret): 0x19
- Debug string: Filter(NTID{Rva: 0xCF6E, Id: 0x11, Name: ZwAllocateVirtualMemory}
- Debug string: Fret): 0x11
- Debug string: Fret): 0x1179
- Debug string: Fret): 0x11E8
- Debug string: Fret): 0x11E8
- Debug string: Fret): 0x1179
- Debug string: Filter(NTID{Rva: 0xCF6E, Id: 0x11, Name: ZwAllocateVirtualMemory}
- Debug string: Fret): 0x11
- Debug string: Fret): 0x11E8
- Debug string: Fret): 0x1179
- Debug string: Fret): 0x11E8
- Debug string: Fret): 0x1179
- Debug string: Fret): 0x11E8
- Debug string: Filter(NTID{Rva: 0xCF6E, Id: 0x11, Name: ZwAllocateVirtualMemory}
- Debug string: Fret): 0x11
- Debug string: Fret): 0x11E8
- Debug string: Fret): 0x1179
- Debug string: Fret): 0x11E8
- Debug string: Fret): 0x1179
- Debug string: Fret): 0x11E8
- Debug string: Fret): 0x1179
- Debug string: Fret): 0x11E8
- Debug string: Fret): 0x1179
- Debug string: Fret): 0x11E8
- Debug string: Fret): 0x1179
- Debug string: Fret): 0x11E8
- Debug string: Fret): 0x11E8
- Debug string: Fret): 0x1179
- Debug string: Fret): 0x11E8
- Debug string: Fret): 0x1179
- Debug string: Filter(NTID{Rva: 0xCF6E, Id: 0x11, Name: ZwAllocateVirtualMemory}
- Debug string: Fret): 0x11
- Debug string: Fret): 0x11E8
- Debug string: Fret): 0x1179
- Debug string: Fret): 0x11E8
- Debug string: Fret): 0x1179
- Debug string: Fret): 0x11E8
- Debug string: Fret): 0x1179
- Debug string: Fret): 0x11E8
- Debug string: Fret): 0x1179
- Debug string: Fret): 0x11E8
- Debug string: Fret): 0x1179
- Debug string: Fret): 0x11E8
- Debug string: Fret): 0x1179
- Debug string: Fret): 0x11E8
- Debug string: Fret): 0x1179
- Debug string: Filter(NTID{Rva: 0xCF6E, Id: 0x11, Name: ZwAllocateVirtualMemory}
- Debug string: Fret): 0x11
- Debug string: Fret): 0x11E8
- Debug string: Fret): 0x1179
- Debug string: Filter(NTID{Rva: 0xCF6E, Id: 0x11, Name: ZwAllocateVirtualMemory}
- Debug string: Fret): 0x11
- Debug string: Fret): 0x11E8
- Debug string: Fret): 0x1179
- Debug string: Fret): 0x11E8
- Debug string: Fret): 0x1179
- Debug string: Fret): 0x11E8
- Debug string: Fret): 0x1179
- Debug string: Fret): 0x11E8
- Debug string: Fret): 0x1179
- Debug string: Fret): 0x11E8
- Debug string: Fret): 0x1179
- Debug string: Fret): 0x11E8
- Debug string: Fret): 0x1179
- Debug string: Filter(NTID{Rva: 0xCF6E, Id: 0x11, Name: ZwAllocateVirtualMemory}
- Debug string: Fret): 0x11
- Debug string: Fret): 0x11E8
- Debug string: Filter(NTID{Rva: 0xD5CE, Id: 0x77, Name: ZwOpenKey}
- Debug string: Fret): 0x77
- Debug string: Filter(NTID{Rva: 0xD5CE, Id: 0x77, Name: ZwOpenKey}
- Debug string: Fret): 0x77
- Debug string: Filter(NTID{Rva: 0xD5CE, Id: 0x77, Name: ZwOpenKey}
- Debug string: Fret): 0x77
- Debug string: Filter(NTID{Rva: 0xD96E, Id: 0xB1, Name: ZwQueryValueKey}
- Debug string: Fret): 0xB1
- Debug string: Filter(NTID{Rva: 0xCFEE, Id: 0x19, Name: ZwClose}
- Debug string: Filter(pZw: 0x1001006E
- Debug string: NtClose(HANDLE: 0x44, OBJECT: \REGISTRY\MACHINE\SYSTEM\Setup)
- Debug string: Fret): 0x19
- Debug string: Filter(NTID{Rva: 0xD75E, Id: 0x90, Name: ZwQueryDefaultUILanguage}
- Debug string: Fret): 0x90
- Debug string: Filter(NTID{Rva: 0xD59E, Id: 0x74, Name: ZwOpenFile}
- Debug string: Fret): 0x74
- Debug string: Filter(NTID{Rva: 0xD17E, Id: 0x32, Name: ZwCreateSection}
- Debug string: Fret): 0x32
- Debug string: Filter(NTID{Rva: 0xD92E, Id: 0xAD, Name: ZwQuerySystemInformation}
- Debug string: Fret): 0xAD
- Debug string: Filter(NTID{Rva: 0xD51E, Id: 0x6C, Name: ZwMapViewOfSection}
- Debug string: Fret): 0x6C
- Debug string: Filter(NTID{Rva: 0xD59E, Id: 0x74, Name: ZwOpenFile}
- Debug string: Fret): 0x74
- Debug string: Filter(NTID{Rva: 0xD82E, Id: 0x9D, Name: ZwQueryInstallUILanguage}
- Debug string: Fret): 0x9D
- Debug string: Filter(NTID{Rva: 0xD74E, Id: 0x8F, Name: ZwQueryDefaultLocale}
- Debug string: Fret): 0x8F
- Debug string: Filter(NTID{Rva: 0xD59E, Id: 0x74, Name: ZwOpenFile}
- Debug string: Fret): 0x74
- Debug string: Filter(NTID{Rva: 0xDADE, Id: 0xC8, Name: ZwRequestWaitReplyPort}
- Debug string: Fret): 0xC8
- Debug string: Filter(NTID{Rva: 0xCFEE, Id: 0x19, Name: ZwClose}
- Debug string: Filter(pZw: 0x1001006E
- Debug string: NtClose(HANDLE: 0x44, OBJECT: \Device\HarddiskVolume1\WINDOWS\system32\shell32.dll)
- Debug string: Fret): 0x19
- Debug string: Filter(NTID{Rva: 0xCFEE, Id: 0x19, Name: ZwClose}
- Debug string: Filter(pZw: 0x1001006E
- Debug string: NtClose(HANDLE: 0x40, OBJECT: (null))
- Debug string: Fret): 0x19
- Debug string: Filter(NTID{Rva: 0xDF0E, Id: 0x10B, Name: ZwUnmapViewOfSection}
- Debug string: Fret): 0x10B
- Debug string: Filter(NTID{Rva: 0xD73E, Id: 0x8E, Name: ZwQueryDebugFilterState}
- Debug string: Fret): 0x8E
- Debug string: Filter(NTID{Rva: 0xD5CE, Id: 0x77, Name: ZwOpenKey}
- Debug string: Fret): 0x77
- Debug string: Filter(NTID{Rva: 0xD73E, Id: 0x8E, Name: ZwQueryDebugFilterState}
- Debug string: Fret): 0x8E
- Debug string: Filter(NTID{Rva: 0xD73E, Id: 0x8E, Name: ZwQueryDebugFilterState}
- Debug string: Fret): 0x8E
- Debug string: Filter(NTID{Rva: 0xCF6E, Id: 0x11, Name: ZwAllocateVirtualMemory}
- Debug string: Fret): 0x11
- Debug string: Filter(NTID{Rva: 0xD70E, Id: 0x8B, Name: ZwQueryAttributesFile}
- Debug string: Fret): 0x8B
- Debug string: Filter(NTID{Rva: 0xD73E, Id: 0x8E, Name: ZwQueryDebugFilterState}
- Debug string: Fret): 0x8E
- Debug string: Filter(NTID{Rva: 0xD73E, Id: 0x8E, Name: ZwQueryDebugFilterState}
- Debug string: Fret): 0x8E
- Debug string: Filter(NTID{Rva: 0xD73E, Id: 0x8E, Name: ZwQueryDebugFilterState}
- Debug string: Fret): 0x8E
- Debug string: Filter(NTID{Rva: 0xD70E, Id: 0x8B, Name: ZwQueryAttributesFile}
- Debug string: Fret): 0x8B
- Debug string: Filter(NTID{Rva: 0xD59E, Id: 0x74, Name: ZwOpenFile}
- Debug string: Fret): 0x74
- Debug string: Filter(NTID{Rva: 0xD73E, Id: 0x8E, Name: ZwQueryDebugFilterState}
- Debug string: Fret): 0x8E
- Debug string: Filter(NTID{Rva: 0xCF6E, Id: 0x11, Name: ZwAllocateVirtualMemory}
- Debug string: Fret): 0x11
- Debug string: Filter(NTID{Rva: 0xCF6E, Id: 0x11, Name: ZwAllocateVirtualMemory}
- Debug string: Fret): 0x11
- Debug string: Filter(NTID{Rva: 0xD5CE, Id: 0x77, Name: ZwOpenKey}
- Debug string: Fret): 0x77
- Debug string: Filter(NTID{Rva: 0xD5CE, Id: 0x77, Name: ZwOpenKey}
- Debug string: Fret): 0x77
- Debug string: Fret): 0x11ED
- Debug string: Fret): 0x11ED
- Debug string: Fret): 0x11ED
- Debug string: Fret): 0x11ED
- Debug string: Fret): 0x11ED
- Debug string: Fret): 0x11ED
- Debug string: Fret): 0x11ED
- Debug string: Fret): 0x11ED
- Debug string: Fret): 0x11ED
- Debug string: Fret): 0x11ED
- Debug string: Fret): 0x11ED
- Debug string: Fret): 0x11ED
- Debug string: Fret): 0x11ED
- Debug string: Fret): 0x11ED
- Debug string: Fret): 0x11ED
- Debug string: Fret): 0x11ED
- Debug string: Filter(NTID{Rva: 0xD5CE, Id: 0x77, Name: ZwOpenKey}
- Debug string: Fret): 0x77
- Debug string: Filter(NTID{Rva: 0xD5CE, Id: 0x77, Name: ZwOpenKey}
- Debug string: Fret): 0x77
- Debug string: Filter(NTID{Rva: 0xD92E, Id: 0xAD, Name: ZwQuerySystemInformation}
- Debug string: Fret): 0xAD
- Debug string: Filter(NTID{Rva: 0xCF6E, Id: 0x11, Name: ZwAllocateVirtualMemory}
- Debug string: Fret): 0x11
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD6EE, Id: 0x89, Name: ZwProtectVirtualMemory}
- Debug string: Fret): 0x89
- Debug string: Filter(NTID{Rva: 0xD8AE, Id: 0xA5, Name: ZwQueryPerformanceCounter}
- Debug string: Fret): 0xA5
- Debug string: Filter(NTID{Rva: 0xD92E, Id: 0xAD, Name: ZwQuerySystemInformation}
- Debug string: Fret): 0xAD
- Debug string: Filter(NTID{Rva: 0xCF6E, Id: 0x11, Name: ZwAllocateVirtualMemory}
- Debug string: Fret): 0x11
- Debug string: Filter(NTID{Rva: 0xCF6E, Id: 0x11, Name: ZwAllocateVirtualMemory}
- Debug string: Fret): 0x11
- Debug string: Filter(NTID{Rva: 0xCF6E, Id: 0x11, Name: ZwAllocateVirtualMemory}
- Debug string: Fret): 0x11
- Debug string: Filter(NTID{Rva: 0xCF6E, Id: 0x11, Name: ZwAllocateVirtualMemory}
- Debug string: Fret): 0x11
- Debug string: Filter(NTID{Rva: 0xD5CE, Id: 0x77, Name: ZwOpenKey}
- Debug string: Fret): 0x77
- Debug string: Filter(NTID{Rva: 0xD5CE, Id: 0x77, Name: ZwOpenKey}
- Debug string: Fret): 0x77
- Debug string: Filter(NTID{Rva: 0xD5CE, Id: 0x77, Name: ZwOpenKey}
- Debug string: Fret): 0x77
- Debug string: Filter(NTID{Rva: 0xD5CE, Id: 0x77, Name: ZwOpenKey}
- Debug string: Fret): 0x77
- Debug string: Filter(NTID{Rva: 0xD5CE, Id: 0x77, Name: ZwOpenKey}
- Debug string: Fret): 0x77
- Debug string: Filter(NTID{Rva: 0xD5CE, Id: 0x77, Name: ZwOpenKey}
- Debug string: Fret): 0x77
- Debug string: Filter(NTID{Rva: 0xD5CE, Id: 0x77, Name: ZwOpenKey}
- Debug string: Fret): 0x77
- Debug string: Filter(NTID{Rva: 0xD5CE, Id: 0x77, Name: ZwOpenKey}
- Debug string: Fret): 0x77
- Debug string: Filter(NTID{Rva: 0xD5CE, Id: 0x77, Name: ZwOpenKey}
- Debug string: Fret): 0x77
- Debug string: Filter(NTID{Rva: 0xD5CE, Id: 0x77, Name: ZwOpenKey}
- Debug string: Fret): 0x77
- Debug string: Filter(NTID{Rva: 0xDE8E, Id: 0x103, Name: ZwTestAlert}
- Debug string: Fret): 0x103
- Debug string: Filter(NTID{Rva: 0xD05E, Id: 0x20, Name: ZwContinue}
- Debug string: Fret): 0x20
- Debug string: Filter(NTID{Rva: 0xDCAE, Id: 0xE5, Name: ZwSetInformationThread}
- Debug string: Fret): 0xE5
- 0100739D Entry point of main module
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement