Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 0021:Ret KERNEL32.LocalFree() retval=00000000 ret=5f8078da
- 0021:Call KERNEL32.LocalAlloc(00000040,00000114) ret=5f805fef
- 0021:Ret KERNEL32.LocalAlloc() retval=024fcc18 ret=5f805fef
- 0021:Call KERNEL32.LocalAlloc(00000040,00000010) ret=5f805fef
- 0021:Ret KERNEL32.LocalAlloc() retval=001343e8 ret=5f805fef
- 0021:Call KERNEL32.LocalAlloc(00000000,00000018) ret=5f805fd0
- 0021:Ret KERNEL32.LocalAlloc() retval=024f6818 ret=5f805fd0
- 0021:Call ntdll.memset(024f6818,00000000,00000018) ret=5f805eff
- 0021:Ret ntdll.memset() retval=024f6818 ret=5f805eff
- 0021:Call KERNEL32.LocalAlloc(00000040,0000104c) ret=5f805fef
- 0021:Ret KERNEL32.LocalAlloc() retval=001a9c68 ret=5f805fef
- 0021:Call KERNEL32.LocalAlloc(00000040,00000010) ret=5f805fef
- 0021:Ret KERNEL32.LocalAlloc() retval=00131ec0 ret=5f805fef
- 0021:Call KERNEL32.LocalAlloc(00000000,00000020) ret=5f805fd0
- 0021:Ret KERNEL32.LocalAlloc() retval=001349c0 ret=5f805fd0
- 0021:Call ntdll.memset(001349c0,00000000,00000020) ret=5f805eff
- 0021:Ret ntdll.memset() retval=001349c0 ret=5f805eff
- 0021:Call KERNEL32.CloseHandle(fffffffe) ret=5f807b6b
- 0021:Ret KERNEL32.CloseHandle() retval=00000000 ret=5f807b6b
- 0021:Call gdi32.DeleteObject(00000bf0) ret=5f803f39
- 0021:Ret gdi32.DeleteObject() retval=00000001 ret=5f803f39
- 0021:Call gdi32.DeleteObject(00000bf4) ret=5f803f39
- 0021:Ret gdi32.DeleteObject() retval=00000001 ret=5f803f39
- 0021:Call gdi32.DeleteObject(00000bf8) ret=5f803f39
- 0021:Ret gdi32.DeleteObject() retval=00000001 ret=5f803f39
- 0021:Call gdi32.DeleteObject(00000bfc) ret=5f803f39
- 0021:Ret gdi32.DeleteObject() retval=00000001 ret=5f803f39
- 0021:Call gdi32.DeleteObject(00000c00) ret=5f803f39
- 0021:Ret gdi32.DeleteObject() retval=00000001 ret=5f803f39
- 0021:Call gdi32.DeleteObject(00000c04) ret=5f803f39
- 0021:Ret gdi32.DeleteObject() retval=00000001 ret=5f803f39
- 0021:Call gdi32.DeleteObject(00000c08) ret=5f803f39
- 0021:Ret gdi32.DeleteObject() retval=00000001 ret=5f803f39
- 0021:Call gdi32.DeleteObject(00000c0c) ret=5f803f39
- 0021:Ret gdi32.DeleteObject() retval=00000001 ret=5f803f39
- 0021:Call gdi32.DeleteObject(00000c10) ret=5f803f39
- 0021:Ret gdi32.DeleteObject() retval=00000001 ret=5f803f39
- 0021:Call KERNEL32.LocalFree(001a9c68) ret=5f8078da
- 0021:Ret KERNEL32.LocalFree() retval=00000000 ret=5f8078da
- 0021:Call KERNEL32.LocalFree(024fcc18) ret=5f8078da
- 0021:Ret KERNEL32.LocalFree() retval=00000000 ret=5f8078da
- 0021:Call msvcrt.free(001a9348) ret=5f806df8
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,001a9348) ret=7e4146c6
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e4146c6
- 0021:Ret msvcrt.free() retval=00000001 ret=5f806df8
- 0021:Call ntdll.RtlDeleteCriticalSection(5f8c8950) ret=5f81137c
- 0021:Ret ntdll.RtlDeleteCriticalSection() retval=00000000 ret=5f81137c
- 0021:Call ntdll.RtlDeleteCriticalSection(5f8c87f8) ret=5f81139a
- 0021:Ret ntdll.RtlDeleteCriticalSection() retval=00000000 ret=5f81139a
- 0021:Call ntdll.RtlDeleteCriticalSection(5f8c8810) ret=5f81139a
- 0021:Ret ntdll.RtlDeleteCriticalSection() retval=00000000 ret=5f81139a
- 0021:Call ntdll.RtlDeleteCriticalSection(5f8c88a0) ret=5f81139a
- 0021:Ret ntdll.RtlDeleteCriticalSection() retval=00000000 ret=5f81139a
- 0021:Call ntdll.RtlDeleteCriticalSection(5f8c8918) ret=5f81139a
- 0021:Ret ntdll.RtlDeleteCriticalSection() retval=00000000 ret=5f81139a
- 0021:Call ntdll.RtlDeleteCriticalSection(5f8c8930) ret=5f81139a
- 0021:Ret ntdll.RtlDeleteCriticalSection() retval=00000000 ret=5f81139a
- 0021:Call KERNEL32.GetModuleHandleA(5f8a3bd8 "MSVCRT40.DLL") ret=5f806b66
- 0021:Ret KERNEL32.GetModuleHandleA() retval=7dba0000 ret=5f806b66
- 0021:Call KERNEL32.FreeLibrary(7dba0000) ret=5f806b6d
- 0021:Ret KERNEL32.FreeLibrary() retval=00000001 ret=5f806b6d
- 0021:Call KERNEL32.TlsFree(00000009) ret=5f810bf9
- 0021:Ret KERNEL32.TlsFree() retval=00000001 ret=5f810bf9
- 0021:Call KERNEL32.GlobalHandle(001a8cf0) ret=5f810c07
- 0021:Ret KERNEL32.GlobalHandle() retval=001a8b6a ret=5f810c07
- 0021:Call KERNEL32.GlobalUnlock(001a8b6a) ret=5f810c10
- 0021:Ret KERNEL32.GlobalUnlock() retval=00000000 ret=5f810c10
- 0021:Call KERNEL32.GlobalFree(001a8b6a) ret=5f810c17
- 0021:Ret KERNEL32.GlobalFree() retval=00000000 ret=5f810c17
- 0021:Call ntdll.RtlDeleteCriticalSection(5f8c6b10) ret=5f810c21
- 0021:Ret ntdll.RtlDeleteCriticalSection() retval=00000000 ret=5f810c21
- 0021:Call KERNEL32.GlobalHandle(001a95d8) ret=5f810c07
- 0021:Ret KERNEL32.GlobalHandle() retval=001a9142 ret=5f810c07
- 0021:Call KERNEL32.GlobalUnlock(001a9142) ret=5f810c10
- 0021:Ret KERNEL32.GlobalUnlock() retval=00000000 ret=5f810c10
- 0021:Call KERNEL32.GlobalFree(001a9142) ret=5f810c17
- 0021:Ret KERNEL32.GlobalFree() retval=00000000 ret=5f810c17
- 0021:Call ntdll.RtlDeleteCriticalSection(5f8c6b48) ret=5f810c21
- 0021:Ret ntdll.RtlDeleteCriticalSection() retval=00000000 ret=5f810c21
- 0021:Ret PE DLL (proc=0x5f806c44,module=0x5f800000 L"MFC40.DLL",reason=PROCESS_DETACH,res=(nil)) retval=1
- 0021:Call PE DLL (proc=0x7dbb5470,module=0x7dba0000 L"msvcrt40.dll",reason=PROCESS_DETACH,res=(nil))
- 0021:Ret PE DLL (proc=0x7dbb5470,module=0x7dba0000 L"msvcrt40.dll",reason=PROCESS_DETACH,res=(nil)) retval=1
- 0021:Ret KERNEL32.FreeLibrary() retval=00000001 ret=7eaa22ed
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,024fca18) ret=7eaa2310
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7eaa2310
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,024fc9f0) ret=7eaa2330
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7eaa2330
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,024fc728) ret=7eaa2866
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7eaa2866
- 0021:Ret ole32.CoFreeUnusedLibraries() retval=00000000 ret=66019433
- 0021:Call ole32.OleUninitialize() ret=66019094
- 0021:Call KERNEL32.GetModuleHandleW(7eb4fd40 L"ole32") ret=7ea9df73
- 0021:Ret KERNEL32.GetModuleHandleW() retval=7ea90000 ret=7ea9df73
- 0021:Call KERNEL32.GlobalFree(00130b22) ret=7eabf22b
- 0021:Ret KERNEL32.GlobalFree() retval=00000000 ret=7eabf22b
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,00134150) ret=7eabf20b
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7eabf20b
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,00000000) ret=7ea9dfdf
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ea9dfdf
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,00134130) ret=7ea9dfff
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ea9dfff
- 0021:Call user32.DestroyWindow(00010076) ret=7eaa41cd
- 0021:Call window proc 0x7eaa3de0 (hwnd=0x10076,msg=WM_DESTROY,wp=00000000,lp=00000000)
- 0021:Call user32.DefWindowProcW(00010076,00000002,00000000,00000000) ret=7ed22e6a
- 0021:Ret user32.DefWindowProcW() retval=00000000 ret=7ed22e6a
- 0021:Ret window proc 0x7eaa3de0 (hwnd=0x10076,msg=WM_DESTROY,wp=00000000,lp=00000000) retval=00000000
- 0021:Call window proc 0x7eaa3de0 (hwnd=0x10076,msg=WM_NCDESTROY,wp=00000000,lp=00000000)
- 0021:Call user32.DefWindowProcW(00010076,00000082,00000000,00000000) ret=7ed22e6a
- 0021:Ret user32.DefWindowProcW() retval=00000000 ret=7ed22e6a
- 0021:Ret window proc 0x7eaa3de0 (hwnd=0x10076,msg=WM_NCDESTROY,wp=00000000,lp=00000000) retval=00000000
- 0021:Ret user32.DestroyWindow() retval=00000001 ret=7eaa41cd
- 0021:Call rpcrt4.RpcServerUnregisterIf(0013f6f4,00000000,00000001) ret=7eada6fe
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,0013f740) ret=7ea4a3a9
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ea4a3a9
- 0021:Ret rpcrt4.RpcServerUnregisterIf() retval=00000000 ret=7eada6fe
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,0013f6e8) ret=7eada730
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7eada730
- 0021:Call rpcrt4.NdrCStdStubBuffer_Release(0013f5d0,7eb72e10) ret=7eb4d377
- 0021:Call rpcrt4.CStdStubBuffer_Disconnect(0013f5d0) ret=7ea1d37f
- 0021:Ret rpcrt4.CStdStubBuffer_Disconnect() retval=00000002 ret=7ea1d37f
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,0013f5d0) ret=7ea1d3ad
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ea1d3ad
- 0021:Ret rpcrt4.NdrCStdStubBuffer_Release() retval=00000000 ret=7eb4d377
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,0013f6d0) ret=7ead6209
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ead6209
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,0013f690) ret=7eaf192d
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7eaf192d
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,00000000) ret=7eabf9a8
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7eabf9a8
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,0013f3d8) ret=7eaf0bcd
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7eaf0bcd
- 0021:Call ntdll.RtlDeleteCriticalSection(0013f600) ret=7eaf1aa1
- 0021:Ret ntdll.RtlDeleteCriticalSection() retval=00000000 ret=7eaf1aa1
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,0013f5f0) ret=7eaf1ac1
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7eaf1ac1
- 0021:Call oleaut32.DllCanUnloadNow() ret=7eaa2880
- 0021:Ret oleaut32.DllCanUnloadNow() retval=00000001 ret=7eaa2880
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,0013f478) ret=7eaa42ca
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7eaa42ca
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,00169cc0) ret=7eaa42ca
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7eaa42ca
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,001aeaa0) ret=7eaa42ca
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7eaa42ca
- 0021:Call ntdll.RtlDeleteCriticalSection(00133c1c) ret=7eaa42ea
- 0021:Ret ntdll.RtlDeleteCriticalSection() retval=00000000 ret=7eaa42ea
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,00133bf8) ret=7eaa430a
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7eaa430a
- 0021:Call ntdll.RtlDeleteCriticalSection(00133bb0) ret=7eacbedc
- 0021:Ret ntdll.RtlDeleteCriticalSection() retval=00000000 ret=7eacbedc
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,00133ba0) ret=7eacbf04
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7eacbf04
- 0021:Call rpcrt4.RpcBindingFree(0033fcb0) ret=7eacbf33
- 0021:Call KERNEL32.FlushFileBuffers(0000005c) ret=7ea504d9
- 0021:Ret KERNEL32.FlushFileBuffers() retval=00000001 ret=7ea504d9
- 0021:Call KERNEL32.CloseHandle(0000005c) ret=7ea504e7
- 0021:Ret KERNEL32.CloseHandle() retval=00000001 ret=7ea504e7
- 0021:Call KERNEL32.CloseHandle(000000a0) ret=7ea50503
- 002b:Ret KERNEL32.ReadFile() retval=00000000 ret=7ed6f5dd
- 002b:Call ntdll.RtlFreeHeap(00110000,00000000,00000000) ret=7ed629c6
- 002b:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed629c6
- 002b:Call ntdll.RtlFreeHeap(00110000,00000000,00000000) ret=7ed64697
- 002b:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed64697
- 002b:Call ntdll.RtlFreeHeap(00110000,00000000,00000000) ret=7ed72c46
- 002b:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed72c46
- 002b:Call ntdll.RtlFreeHeap(00110000,00000000,00000000) ret=7ed629c6
- 002b:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed629c6
- 002b:Call ntdll.RtlFreeHeap(00110000,00000000,00000000) ret=7ed64d85
- 002b:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed64d85
- 002b:Call ntdll.RtlFreeHeap(00110000,00000000,00000000) ret=7ed64a43
- 002b:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed64a43
- 002b:Call ntdll.RtlFreeHeap(00110000,00000000,00117938) ret=7ed67b34
- 002b:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed67b34
- 002b:Call KERNEL32.FlushFileBuffers(00000034) ret=7ed6f4d9
- 002b:Ret KERNEL32.FlushFileBuffers() retval=00000001 ret=7ed6f4d9
- 002b:Call KERNEL32.CloseHandle(00000034) ret=7ed6f4e7
- 0021:Ret KERNEL32.CloseHandle() retval=00000001 ret=7ea50503
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,001446b0) ret=7ea3c576
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ea3c576
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,00144698) ret=7e002b:Ca0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ea3c576
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,00000000) ret=7ea517d1
- 002b:Ret KERNEL32.CloseHandle() retval=00000001 ret=7ed6f5002002b:Call ntdll.RtlFreeHeap(00110000,00000000,001176c8) ret=7ed5b5002002b:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed5b5002002b:Call ntdll.RtlFreeHeap(00110000,00000000,00000000) ret=7ed5b5002002b:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed5b5002002b:Call ntdll.RtlFreeHeap(00110000,00000000,00000000) ret=7ed707002002b:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed7070021:Call ntdll.RtlFreeHeap(00110000,00000000,001445d0) ret=7ea3a790
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ea3a790
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,001445b8) ret=7ea3a7b3
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ea3a7b3
- 0021:Call ntdll.RtlDeleteCriticalSection(00144560) ret=7ea3002b:0021:Ret ntdll.RtlDeleteCriticalSection() retval=00000000 ret=7002b:Ret0021:Call ntdll.RtlFreeHeap(00110000,00000000,00144002b:Call ntdll.Rt0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7002b:Ret0021:Call ntdll.RtlFreeHeap(00110000,00000000,00144002b:Call ntdll.Rt0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ea3c576
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,00144500) ret=7ea3c576
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ea3c576
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,001444e8) ret002b:Call 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ea3c576
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,00000000) ret002b:Call 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ea3ed2d
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,00144498) ret002b:Call 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ea3ed6b
- 0021:Ret rpcrt4.RpcBindingFree() retval=00000000 ret=7eacb002b0021:Ret ole32.OleUninitialize() retval=00000000 ret=66019094
- 0021:Call KERNEL32.HeapDestroy(01ac8000) ret=660190bd
- 002b:Call ntdll.RtlFreeHeap(00110000,00000000,00117830) ret=7ed5dd6b
- 002b:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed5dd6b
- 002b:Call ntdll.RtlFreeHeap(00110000,00000000,00117630) ret=7ed7081e
- 0021:Ret KERNEL32.HeapDestroy() retval=00000001 ret=660190bd
- 0021:Call KERNEL32.FreeLibrary(7eb80000) ret=6603793a
- 0021:Ret KERNEL32.FreeLibrary() retval=00000001 ret=6603793a
- 0021:Call KERNEL32.FreeLibrary(7e930000) ret=660194c3
- 0021:Ret KERNEL32.FreeLibrary() retval=00000001 ret=660194c3
- 0021:Call KERNEL32.ReleaseSemaphore(00000040,00000001,00000000) ret=6002b:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed714db
- 002b:Ret PE DLL (proc=0x7ed75050,module=0x7ed30000 L"rpcrt4.dll",reason=THREAD_DETACH,res=(nil)) retval=1
- 0021:Ret KERNEL32.ReleaseSemaphore() retval=00000001 ret=660194fa
- 0021:Call KERNEL32.GetCurrentThreadId() ret=660195d1
- 0021:Ret KERNEL32.GetCurrentThreadId() retval=00000021 ret=660195d1
- 0021:Call ntdll.RtlFreeHeap(00cf0000,00000000,00cf0240) ret=660195f3
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=660195f3
- 0021:Call ntdll.RtlFreeHeap(00cf0000,00000000,00cf0138) ret=66019626
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=66019626
- 0021:Call KERNEL32.ExitProcess(00000000) ret=6600de50
- 0021:Call PE DLL (proc=0x7ca92ba0,module=0x7ca80000 L"wsock32.dll",reason=PROCESS_DETACH,res=0x1)
- 0021:Ret PE DLL (proc=0x7ca92ba0,module=0x7ca80000 L"wsock32.dll",reason=PROCESS_DETACH,res=0x1) retval=1
- 0021:Call PE DLL (proc=0x7ca496c0,module=0x7ca30000 L"iphlpapi.dll",reason=PROCESS_DETACH,res=0x1)
- 0021:Ret PE DLL (proc=0x7ca496c0,module=0x7ca30000 L"iphlpapi.dll",reason=PROCESS_DETACH,res=0x1) retval=1
- 0021:Call PE DLL (proc=0x7ca77ad0,module=0x7ca60000 L"ws2_32.dll",reason=PROCESS_DETACH,res=0x1)
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,00000000) ret=7ca6574d
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ca6574d
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,024fe6b8) ret=7ca65770
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ca65770
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,00000000) ret=7ca65793
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ca65793
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,024fe8e0) ret=7ca657c8
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ca657c8
- 0021:Ret PE DLL (proc=0x7ca77ad0,module=0x7ca60000 L"ws2_32.dll",reason=PROCESS_DETACH,res=0x1) retval=1
- 0021:Call PE DLL (proc=0x7db85b10,module=0x7db30000 L"windowscodecs.dll",reason=PROCESS_DETACH,res=0x1)
- 0021:Ret PE DLL (proc=0x7db85b10,module=0x7db30000 L"windowscodecs.dll",reason=PROCESS_DETACH,res=0x1) retval=1
- 0021:Call PE DLL (proc=0x7e053360,module=0x7dfb0000 L"comctl32.dll",reason=PROCESS_DETACH,res=0x1)
- 0021:Call user32.UnregisterClassW(0033fb02 L"SysAnimate32",00000000) ret=7dfbf677
- 0021:Ret user32.UnregisterClassW() retval=00000001 ret=7dfbf677
- 0021:Call user32.UnregisterClassW(0033fb02 L"ComboBoxEx32",00000000) ret=7dfc5497
- 0021:Ret user32.UnregisterClassW() retval=00000001 ret=7dfc5497
- 0021:Call user32.UnregisterClassW(0033faf8 L"SysDateTimePick32",00000000) ret=7dfcde25
- 0021:Ret user32.UnregisterClassW() retval=00000001 ret=7dfcde25
- 0021:Call user32.UnregisterClassW(0033fafe L"flatsb_class32",00000000) ret=7dfd10b3
- 0021:Ret user32.UnregisterClassW() retval=00000001 ret=7dfd10b3
- 0021:Call user32.UnregisterClassW(0033fb04 L"SysHeader32",00000000) ret=7dfd5b81
- 0021:Ret user32.UnregisterClassW() retval=00000001 ret=7dfd5b81
- 0021:Call user32.UnregisterClassW(0033fafc L"msctls_hotkey32",00000000) ret=7dfd6ee9
- 0021:Ret user32.UnregisterClassW() retval=00000001 ret=7dfd6ee9
- 0021:Call user32.UnregisterClassW(0033fafe L"SysIPAddress32",00000000) ret=7dfe0b83
- 0021:Ret user32.UnregisterClassW() retval=00000001 ret=7dfe0b83
- 0021:Call user32.UnregisterClassW(0033fb00 L"SysListView32",00000000) ret=7dffbe8d
- 0021:Ret user32.UnregisterClassW() retval=00000001 ret=7dffbe8d
- 0021:Call user32.UnregisterClassW(0033fb00 L"SysMonthCal32",00000000) ret=7e0035bd
- 0021:Ret user32.UnregisterClassW() retval=00000001 ret=7e0035bd
- 0021:Call user32.UnregisterClassW(0033fb00 L"NativeFontCtl",00000000) ret=7e00393d
- 0021:Ret user32.UnregisterClassW() retval=00000001 ret=7e00393d
- 0021:Call user32.UnregisterClassW(0033fb0a L"SysPager",00000000) ret=7e0067df
- 0021:Ret user32.UnregisterClassW() retval=00000001 ret=7e0067df
- 0021:Call user32.UnregisterClassW(0033faf8 L"msctls_progress32",00000000) ret=7e007fa5
- 0021:Ret user32.UnregisterClassW() retval=00000001 ret=7e007fa5
- 0021:Call user32.UnregisterClassW(0033fb00 L"ReBarWindow32",00000000) ret=7e0190dd
- 0021:Ret user32.UnregisterClassW() retval=00000001 ret=7e0190dd
- 0021:Call user32.UnregisterClassW(0033faf6 L"msctls_statusbar32",00000000) ret=7e01c68b
- 0021:Ret user32.UnregisterClassW() retval=00000001 ret=7e01c68b
- 0021:Call user32.UnregisterClassW(0033fb0c L"SysLink",00000000) ret=7e020ef9
- 0021:Ret user32.UnregisterClassW() retval=00000001 ret=7e020ef9
- 0021:Call user32.UnregisterClassW(0033fafc L"SysTabControl32",00000000) ret=7e027ee9
- 0021:Ret user32.UnregisterClassW() retval=00000001 ret=7e027ee9
- 0021:Call user32.UnregisterClassW(0033fafc L"ToolbarWindow32",00000000) ret=7e03ab49
- 0021:Ret user32.UnregisterClassW() retval=00000001 ret=7e03ab49
- 0021:Call user32.DestroyIcon(000100ba) ret=7e03fab0
- 0021:Ret user32.DestroyIcon() retval=00000001 ret=7e03fab0
- 0021:Call user32.DestroyIcon(000100bc) ret=7e03fac1
- 0021:Ret user32.DestroyIcon() retval=00000001 ret=7e03fac1
- 0021:Call user32.DestroyIcon(000100be) ret=7e03fad2
- 0021:Ret user32.DestroyIcon() retval=00000001 ret=7e03fad2
- 0021:Call user32.UnregisterClassW(0033fafa L"tooltips_class32",00000000) ret=7e03fb4e
- 0021:Ret user32.UnregisterClassW() retval=00000001 ret=7e03fb4e
- 0021:Call user32.UnregisterClassW(0033faf8 L"msctls_trackbar32",00000000) ret=7e043aa5
- 0021:Ret user32.UnregisterClassW() retval=00000001 ret=7e043aa5
- 0021:Call user32.UnregisterClassW(0033fb00 L"SysTreeView32",00000000) ret=7e050ccd
- 0021:Ret user32.UnregisterClassW() retval=00000001 ret=7e050ccd
- 0021:Call user32.UnregisterClassW(0033fafc L"msctls_updown32",00000000) ret=7e053219
- 0021:Ret user32.UnregisterClassW() retval=00000001 ret=7e053219
- 0021:Call gdi32.DeleteObject(000005b0) ret=7dfc99c5
- 0021:Ret gdi32.DeleteObject() retval=00000001 ret=7dfc99c5
- 0021:Call gdi32.DeleteObject(000005a8) ret=7dfc99dc
- 0021:Ret gdi32.DeleteObject() retval=00000001 ret=7dfc99dc
- 0021:Call KERNEL32.GlobalDeleteAtom(0000c016) ret=7dfc99f8
- 0021:Ret KERNEL32.GlobalDeleteAtom() retval=00000000 ret=7dfc99f8
- 0021:Call KERNEL32.FreeLibrary(7df40000) ret=7e053341
- 0021:Ret KERNEL32.FreeLibrary() retval=00000001 ret=7e053341
- 0021:Ret PE DLL (proc=0x7e053360,module=0x7dfb0000 L"comctl32.dll",reason=PROCESS_DETACH,res=0x1) retval=1
- 0021:Call PE DLL (proc=0x7df5aa90,module=0x7df40000 L"uxtheme.dll",reason=PROCESS_DETACH,res=0x1)
- 0021:Ret PE DLL (proc=0x7df5aa90,module=0x7df40000 L"uxtheme.dll",reason=PROCESS_DETACH,res=0x1) retval=1
- 0021:Call PE DLL (proc=0x7e0e3840,module=0x7e0b0000 L"shlwapi.dll",reason=PROCESS_DETACH,res=0x1)
- 0021:Call KERNEL32.TlsFree(00000006) ret=7e0d5ea2
- 0021:Ret KERNEL32.TlsFree() retval=00000001 ret=7e0d5ea2
- 0021:Ret PE DLL (proc=0x7e0e3840,module=0x7e0b0000 L"shlwapi.dll",reason=PROCESS_DETACH,res=0x1) retval=1
- 0021:Call PE DLL (proc=0x7e440c70,module=0x7e3f0000 L"msvcrt.dll",reason=PROCESS_DETACH,res=0x1)
- 0021:Call ntdll.RtlDeleteCriticalSection(7e467f00) ret=7e418140
- 0021:Ret ntdll.RtlDeleteCriticalSection() retval=00000000 ret=7e418140
- 0021:Call ntdll.RtlDeleteCriticalSection(7e467f38) ret=7e418140
- 0021:Ret ntdll.RtlDeleteCriticalSection() retval=00000000 ret=7e418140
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,00000000) ret=7e4146c6
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e4146c6
- 0021:Call KERNEL32.CloseHandle(0000013b) ret=7e40d666
- 0021:Ret KERNEL32.CloseHandle() retval=00000001 ret=7e40d666
- 0021:Call KERNEL32.GetStdHandle(fffffff6) ret=7e40d6ce
- 0021:Ret KERNEL32.GetStdHandle() retval=0000000f ret=7e40d6ce
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,00000000) ret=7e4146c6
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e4146c6
- 0021:Call KERNEL32.CloseHandle(0000013c) ret=7e40d666
- 0021:Ret KERNEL32.CloseHandle() retval=00000001 ret=7e40d666
- 0021:Call KERNEL32.GetStdHandle(fffffff5) ret=7e40d83c
- 0021:Ret KERNEL32.GetStdHandle() retval=00000010 ret=7e40d83c
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,00000000) ret=7e4146c6
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e4146c6
- 0021:Call KERNEL32.CloseHandle(00000140) ret=7e40d666
- 0021:Ret KERNEL32.CloseHandle() retval=00000001 ret=7e40d666
- 0021:Call KERNEL32.GetStdHandle(fffffff4) ret=7e40d7f4
- 0021:Ret KERNEL32.GetStdHandle() retval=00000014 ret=7e40d7f4
- 0021:Call ntdll.RtlDeleteCriticalSection(7e465a80) ret=7e4114bb
- 0021:Ret ntdll.RtlDeleteCriticalSection() retval=00000000 ret=7e4114bb
- 0021:Call KERNEL32.CloseHandle(00000147) ret=7e3fffd3
- 0021:Ret KERNEL32.CloseHandle() retval=00000001 ret=7e3fffd3
- 0021:Call KERNEL32.CloseHandle(ffffffff) ret=7e3fffe4
- 0021:Ret KERNEL32.CloseHandle() retval=00000000 ret=7e3fffe4
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,001538f8) ret=7e4048d7
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e4048d7
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,00154710) ret=7e4048ff
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e4048ff
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,00152ae0) ret=7e404927
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e404927
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,00000000) ret=7e40494f
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e40494f
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,00151dd0) ret=7e404977
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e404977
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,00151ee0) ret=7e40499f
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e40499f
- 0021:Call KERNEL32.SetConsoleCtrlHandler(7e409f70,00000000) ret=7e40b048
- 0021:Ret KERNEL32.SetConsoleCtrlHandler() retval=00000001 ret=7e40b048
- 0021:Call KERNEL32.SetUnhandledExceptionFilter(00000000) ret=7e40b057
- 0021:Ret KERNEL32.SetUnhandledExceptionFilter() retval=7e409fd0 ret=7e40b057
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,00000000) ret=7e418447
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e418447
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,00000000) ret=7e41846a
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e41846a
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,00000000) ret=7e41848d
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e41848d
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,00000000) ret=7e4184b0
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e4184b0
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,00000000) ret=7e4184d3
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e4184d3
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,001515c8) ret=7e4184fe
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e4184fe
- 0021:Call KERNEL32.TlsFree(00000005) ret=7e41850b
- 0021:Ret KERNEL32.TlsFree() retval=00000001 ret=7e41850b
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,00151b50) ret=7e4146c6
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e4146c6
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,00000000) ret=7e4146c6
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e4146c6
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,00151b68) ret=7e4146c6
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e4146c6
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,00000000) ret=7e4146c6
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e4146c6
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,00151c28) ret=7e4146c6
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e4146c6
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,00000000) ret=7e4146c6
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e4146c6
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,00151c88) ret=7e4146c6
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e4146c6
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,00000000) ret=7e4146c6
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e4146c6
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,00151ca0) ret=7e4146c6
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e4146c6
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,00000000) ret=7e4146c6
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e4146c6
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,00151c40) ret=7e4146c6
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e4146c6
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,00151c58) ret=7e4146c6
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e4146c6
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,00151c70) ret=7e4146c6
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e4146c6
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,00151b80) ret=7e4146c6
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e4146c6
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,00151b98) ret=7e4146c6
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e4146c6
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,00151bb0) ret=7e4146c6
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e4146c6
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,00151bc8) ret=7e4146c6
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e4146c6
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,00151be0) ret=7e4146c6
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e4146c6
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,00151bf8) ret=7e4146c6
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e4146c6
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,00151c10) ret=7e4146c6
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e4146c6
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,00000000) ret=7e4146c6
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e4146c6
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,00000000) ret=7e4146c6
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e4146c6
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,00000000) ret=7e4146c6
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e4146c6
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,0014ec10) ret=7e4146c6
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e4146c6
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,00000000) ret=7e4146c6
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e4146c6
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,00000000) ret=7e4146c6
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e4146c6
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,00151940) ret=7e4146c6
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e4146c6
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,00151a48) ret=7e4146c6
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e4146c6
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,00151638) ret=7e4146c6
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e4146c6
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,00151718) ret=7e4146c6
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e4146c6
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,0014e9a8) ret=7e4146c6
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e4146c6
- 0021:Ret PE DLL (proc=0x7e440c70,module=0x7e3f0000 L"msvcrt.dll",reason=PROCESS_DETACH,res=0x1) retval=1
- 0021:Call PE DLL (proc=0x66001ad8,module=0x66000000 L"MSVBVM60.DLL",reason=PROCESS_DETACH,res=0x1)
- 0021:Call KERNEL32.GetCurrentThreadId() ret=66003528
- 0021:Ret KERNEL32.GetCurrentThreadId() retval=00000021 ret=66003528
- 0021:Call KERNEL32.GetCurrentThreadId() ret=66003528
- 0021:Ret KERNEL32.GetCurrentThreadId() retval=00000021 ret=66003528
- 0021:Call KERNEL32.TlsFree(00000003) ret=660036d1
- 0021:Ret KERNEL32.TlsFree() retval=00000001 ret=660036d1
- 0021:Call KERNEL32.HeapDestroy(00cf0000) ret=66003709
- 0021:Ret KERNEL32.HeapDestroy() retval=00000001 ret=66003709
- 0021:Call ntdll.RtlDeleteCriticalSection(6610ec34) ret=66019641
- 0021:Ret ntdll.RtlDeleteCriticalSection() retval=00000000 ret=66019641
- 0021:Call ntdll.RtlDeleteCriticalSection(6610e664) ret=6600388d
- 0021:Ret ntdll.RtlDeleteCriticalSection() retval=00000000 ret=6600388d
- 0021:Call ntdll.RtlDeleteCriticalSection(6610e644) ret=660038aa
- 0021:Ret ntdll.RtlDeleteCriticalSection() retval=00000000 ret=660038aa
- 0021:Call ntdll.RtlDeleteCriticalSection(6610e59c) ret=660038c7
- 0021:Ret ntdll.RtlDeleteCriticalSection() retval=00000000 ret=660038c7
- 0021:Call KERNEL32.CloseHandle(00000038) ret=66003952
- 0021:Ret KERNEL32.CloseHandle() retval=00000001 ret=66003952
- 0021:Call ntdll.RtlDeleteCriticalSection(6610e564) ret=6600396a
- 0021:Ret ntdll.RtlDeleteCriticalSection() retval=00000000 ret=6600396a
- 0021:Call ntdll.RtlDeleteCriticalSection(6610e544) ret=66003977
- 0021:Ret ntdll.RtlDeleteCriticalSection() retval=00000000 ret=66003977
- 0021:Call ntdll.RtlDeleteCriticalSection(6610e524) ret=66003984
- 0021:Ret ntdll.RtlDeleteCriticalSection() retval=00000000 ret=66003984
- 0021:Call ntdll.RtlDeleteCriticalSection(6610e4fc) ret=660038fe
- 0021:Ret ntdll.RtlDeleteCriticalSection() retval=00000000 ret=660038fe
- 0021:Call ntdll.RtlDeleteCriticalSection(6610e4dc) ret=6600390d
- 0021:Ret ntdll.RtlDeleteCriticalSection() retval=00000000 ret=6600390d
- 0021:Call ntdll.RtlDeleteCriticalSection(6610e4bc) ret=6600391a
- 0021:Ret ntdll.RtlDeleteCriticalSection() retval=00000000 ret=6600391a
- 0021:Call ntdll.RtlDeleteCriticalSection(6610e49c) ret=66003927
- 0021:Ret ntdll.RtlDeleteCriticalSection() retval=00000000 ret=66003927
- 0021:Call KERNEL32.InitializeCriticalSection(008f0ec0) ret=66001f4a
- 0021:Ret KERNEL32.InitializeCriticalSection() retval=00000001 ret=66001f4a
- 0021:Call KERNEL32.InitializeCriticalSection(008f0ee0) ret=66001f4a
- 0021:Ret KERNEL32.InitializeCriticalSection() retval=00000001 ret=66001f4a
- 0021:Call KERNEL32.InitializeCriticalSection(008f0f00) ret=66001f4a
- 0021:Ret KERNEL32.InitializeCriticalSection() retval=00000001 ret=66001f4a
- 0021:Call KERNEL32.InitializeCriticalSection(008f0f20) ret=66001f4a
- 0021:Ret KERNEL32.InitializeCriticalSection() retval=00000001 ret=66001f4a
- 0021:Call ntdll.RtlDeleteCriticalSection(007d8ec8) ret=66003c1a
- 0021:Ret ntdll.RtlDeleteCriticalSection() retval=00000000 ret=66003c1a
- 0021:Call ntdll.RtlFreeHeap(007d8000,00000000,007d8e50) ret=6600275a
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=6600275a
- 0021:Call ntdll.RtlDeleteCriticalSection(008f0ec0) ret=66003ca4
- 0021:Ret ntdll.RtlDeleteCriticalSection() retval=00000000 ret=66003ca4
- 0021:Call ntdll.RtlDeleteCriticalSection(008f0d80) ret=66003ca4
- 0021:Ret ntdll.RtlDeleteCriticalSection() retval=00000000 ret=66003ca4
- 0021:Call ntdll.RtlDeleteCriticalSection(008f0d60) ret=66003ca4
- 0021:Ret ntdll.RtlDeleteCriticalSection() retval=00000000 ret=66003ca4
- 0021:Call ntdll.RtlDeleteCriticalSection(008f0da0) ret=66003ca4
- 0021:Ret ntdll.RtlDeleteCriticalSection() retval=00000000 ret=66003ca4
- 0021:Call ntdll.RtlDeleteCriticalSection(008f0180) ret=66003ca4
- 0021:Ret ntdll.RtlDeleteCriticalSection() retval=00000000 ret=66003ca4
- 0021:Call ntdll.RtlDeleteCriticalSection(008f0ee0) ret=66003ca4
- 0021:Ret ntdll.RtlDeleteCriticalSection() retval=00000000 ret=66003ca4
- 0021:Call ntdll.RtlDeleteCriticalSection(008f0f00) ret=66003ca4
- 0021:Ret ntdll.RtlDeleteCriticalSection() retval=00000000 ret=66003ca4
- 0021:Call ntdll.RtlDeleteCriticalSection(008f0f20) ret=66003ca4
- 0021:Ret ntdll.RtlDeleteCriticalSection() retval=00000000 ret=66003ca4
- 0021:Call ntdll.RtlDeleteCriticalSection(6610c148) ret=66003c64
- 0021:Ret ntdll.RtlDeleteCriticalSection() retval=00000000 ret=66003c64
- 0021:Call ntdll.RtlDeleteCriticalSection(6610c160) ret=66003c6d
- 0021:Ret ntdll.RtlDeleteCriticalSection() retval=00000000 ret=66003c6d
- 0021:Call ntdll.RtlDeleteCriticalSection(6610c130) ret=66003c75
- 0021:Ret ntdll.RtlDeleteCriticalSection() retval=00000000 ret=66003c75
- 0021:Call ntdll.RtlDeleteCriticalSection(6610c118) ret=66003c7e
- 0021:Ret ntdll.RtlDeleteCriticalSection() retval=00000000 ret=66003c7e
- 0021:Call KERNEL32.TlsFree(00000002) ret=66003c32
- 0021:Ret KERNEL32.TlsFree() retval=00000001 ret=66003c32
- 0021:Call KERNEL32.VirtualFree(008f0000,00000000,00008000) ret=66003d0c
- 0021:Ret KERNEL32.VirtualFree() retval=00000001 ret=66003d0c
- 0021:Call KERNEL32.HeapDestroy(007d8000) ret=66003d22
- 0021:Ret KERNEL32.HeapDestroy() retval=00000001 ret=66003d22
- 0021:Ret PE DLL (proc=0x66001ad8,module=0x66000000 L"MSVBVM60.DLL",reason=PROCESS_DETACH,res=0x1) retval=1
- 0021:Call PE DLL (proc=0x7e9d62c0,module=0x7e930000 L"oleaut32.dll",reason=PROCESS_DETACH,res=0x1)
- 0021:Call KERNEL32.FreeLibrary(7db30000) ret=7e9d62a1
- 0021:Ret KERNEL32.FreeLibrary() retval=00000001 ret=7e9d62a1
- 0021:Ret PE DLL (proc=0x7e9d62c0,module=0x7e930000 L"oleaut32.dll",reason=PROCESS_DETACH,res=0x1) retval=1
- 0021:Call PE DLL (proc=0x7eb4d440,module=0x7ea90000 L"ole32.dll",reason=PROCESS_DETACH,res=0x1)
- 0021:Call user32.UnregisterClassW(7eb51600 L"OleMainThreadWndClass 0x######## ",7ea90000) ret=7eaaaa0e
- 0021:Ret user32.UnregisterClassW() retval=00000001 ret=7eaaaa0e
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,0013f588) ret=7eaaaa7a
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7eaaaa7a
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,0013f560) ret=7eaaaa9a
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7eaaaa9a
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,0019dc08) ret=7eaaaa7a
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7eaaaa7a
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,0016a3f8) ret=7eaaaa9a
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7eaaaa9a
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,001aeac0) ret=7eaaaa7a
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7eaaaa7a
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,001aec40) ret=7eaaaa9a
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7eaaaa9a
- 0021:Ret PE DLL (proc=0x7eb4d440,module=0x7ea90000 L"ole32.dll",reason=PROCESS_DETACH,res=0x1) retval=1
- 0021:Call PE DLL (proc=0x7ea56050,module=0x7ea10000 L"rpcrt4.dll",reason=PROCESS_DETACH,res=0x1)
- 0021:Call KERNEL32.WaitForSingleObject(00000054,ffffffff) ret=7ea46dcc
- 0021:Ret KERNEL32.WaitForSingleObject() retval=00000000 ret=7ea46dcc
- 0021:Call KERNEL32.SetEvent(00000048) ret=7ea4c314
- 0022:Ret KERNEL32.WaitForMultipleObjectsEx() retval=00000000 ret=7ea5138f
- 0022:Call ntdll.RtlFreeHeap(00110000,00000000,0013f7a8) ret=7ea4bc46
- 0022:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ea4bc46
- 0022:Call KERNEL32.FlushFileBuffers(0000004c) ret=7ea504d9
- 0021:Ret KERNEL32.SetEvent() retval=00000001 ret=7ea4c314
- 0021:Call KERNEL32.WaitForSingleObject(00000058,ffffffff) ret=7ea46dea
- 0022:Ret KERNEL32.FlushFileBuffers() retval=00000001 ret=7ea504d9
- 0022:Call KERNEL32.CloseHandle(0000004c) ret=7ea504e7
- 0022:Ret KERNEL32.CloseHandle() retval=00000001 ret=7ea504e7
- 0022:Call KERNEL32.CloseHandle(00000050) ret=7ea50503
- 0022:Ret KERNEL32.CloseHandle() retval=00000001 ret=7ea50503
- 0022:Call KERNEL32.SetEvent(00000058) ret=7ea46f63
- 0022:Ret KERNEL32.SetEvent() retval=00000001 ret=7ea46f63
- 0021:Ret KERNEL32.WaitForSingleObject() retval=00000000 ret=7ea46dea
- 0021:Call KERNEL32.ReleaseMutex(00000054) ret=7ea46df8
- 0021:Ret KERNEL32.ReleaseMutex() retval=00000001 ret=7ea46df8
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,0013f438) ret=7ea3c576
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ea3c576
- 0021:Call ntdll.RtlDeleteCriticalSection(0013f408) ret=7ea49706
- 0021:Ret ntdll.RtlDeleteCriticalSection() retval=00000000 ret=7ea49706
- 0021:Call KERNEL32.CloseHandle(00000054) ret=7ea49714
- 0021:Ret KERNEL32.CloseHandle() retval=00000001 ret=7ea49714
- 0021:Call KERNEL32.CloseHandle(00000058) ret=7ea49722
- 0021:Ret KERNEL32.CloseHandle() retval=00000001 ret=7ea49722
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,0013f3f0) ret=7ea49753
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ea49753
- 0021:Ret PE DLL (proc=0x7ea56050,module=0x7ea10000 L"rpcrt4.dll",reason=PROCESS_DETACH,res=0x1) retval=1
- 0021:Call PE DLL (proc=0x7ed28910,module=0x7ec90000 L"user32.dll",reason=PROCESS_DETACH,res=0x1)
- 0021:Ret PE DLL (proc=0x7ed28910,module=0x7ec90000 L"user32.dll",reason=PROCESS_DETACH,res=0x1) retval=1
- 0021:Call PE DLL (proc=0x7e79ba10,module=0x7e730000 L"winex11.drv",reason=PROCESS_DETACH,res=0x1)
- 0021:Ret PE DLL (proc=0x7e79ba10,module=0x7e730000 L"winex11.drv",reason=PROCESS_DETACH,res=0x1) retval=1
- 0021:Call PE DLL (proc=0x7e58fef0,module=0x7e580000 L"imm32.dll",reason=PROCESS_DETACH,res=0x1)
- 0021:Call winex11.drv.ImeSelect(001356d0,00000000) ret=7e58dfe8
- 0021:Ret winex11.drv.ImeSelect() retval=00000001 ret=7e58dfe8
- 0021:Call user32.GetKeyboardLayout(00000000) ret=7e58dff7
- 0021:Ret user32.GetKeyboardLayout() retval=00000000 ret=7e58dff7
- 0021:Call user32.SendMessageW(00000000,00000285,00000000,00000000) ret=7e58e019
- 0021:Ret user32.SendMessageW() retval=00000000 ret=7e58e019
- 0021:Call user32.DestroyWindow(00000000) ret=7e58e038
- 0021:Ret user32.DestroyWindow() retval=00000000 ret=7e58e038
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,00135ac0) ret=7e58df96
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e58df96
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,00135d60) ret=7e58df96
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e58df96
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,00135e00) ret=7e58df96
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e58df96
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,00135e30) ret=7e58df96
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e58df96
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,00135b38) ret=7e58df96
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e58df96
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,001356d0) ret=7e58e0ad
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e58e0ad
- 0021:Call user32.DestroyWindow(00000000) ret=7e58e17c
- 0021:Ret user32.DestroyWindow() retval=00000000 ret=7e58e17c
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,00135358) ret=7e58e19c
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e58e19c
- 0021:Call winex11.drv.ImeDestroy(00000001) ret=7e58e26c
- 0021:Ret winex11.drv.ImeDestroy() retval=00000001 ret=7e58e26c
- 0021:Call KERNEL32.FreeLibrary(7e730000) ret=7e58e27a
- 0021:Ret KERNEL32.FreeLibrary() retval=00000001 ret=7e58e27a
- 0021:Call ntdll.RtlFreeHeap(00110000,00000000,00135370) ret=7e58e29a
- 0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e58e29a
- 0021:Call KERNEL32.TlsFree(00000000) ret=7e58e2b5
- 0021:Ret KERNEL32.TlsFree() retval=00000001 ret=7e58e2b5
- 0021:Ret PE DLL (proc=0x7e58fef0,module=0x7e580000 L"imm32.dll",reason=PROCESS_DETACH,res=0x1) retval=1
- 0021:Call PE DLL (proc=0x7eb88ee0,module=0x7eb80000 L"version.dll",reason=PROCESS_DETACH,res=0x1)
- 0021:Ret PE DLL (proc=0x7eb88ee0,module=0x7eb80000 L"version.dll",reason=PROCESS_DETACH,res=0x1) retval=1
- 0021:Call PE DLL (proc=0x7ec50560,module=0x7ebf0000 L"gdi32.dll",reason=PROCESS_DETACH,res=0x1)
- 0021:Ret PE DLL (proc=0x7ec50560,module=0x7ebf0000 L"gdi32.dll",reason=PROCESS_DETACH,res=0x1) retval=1
- 0021:Call PE DLL (proc=0x7ebd6300,module=0x7eba0000 L"advapi32.dll",reason=PROCESS_DETACH,res=0x1)
- 0021:Ret PE DLL (proc=0x7ebd6300,module=0x7eba0000 L"advapi32.dll",reason=PROCESS_DETACH,res=0x1) retval=1
- 0021:Call PE DLL (proc=0x7b8790f0,module=0x7b810000 L"KERNEL32.dll",reason=PROCESS_DETACH,res=0x1)
- 0021:Ret PE DLL (proc=0x7b8790f0,module=0x7b810000 L"KERNEL32.dll",reason=PROCESS_DETACH,res=0x1) retval=1
- 0021:Call PE DLL (proc=0x7bc88ea0,module=0x7bc10000 L"ntdll.dll",reason=PROCESS_DETACH,res=0x1)
- 0021:Ret PE DLL (proc=0x7bc88ea0,module=0x7bc10000 L"ntdll.dll",reason=PROCESS_DETACH,res=0x1) retval=1
- 001f:Ret user32.GetMessageW() retval=00000001 ret=7ed95eb3
- 001f:Call user32.DispatchMessageW(0033f6b8) ret=7ed95e90
- 001f:Call window proc 0x7ed958d0 (hwnd=0x20030,msg=WM_CLOSE,wp=00000000,lp=00000000)
- 001f:Call user32.PostQuitMessage(00000000) ret=7ed9599c
- 001f:Ret user32.PostQuitMessage() retval=00000000 ret=7ed9599c
- 001f:Ret window proc 0x7ed958d0 (hwnd=0x20030,msg=WM_CLOSE,wp=00000000,lp=00000000) retval=00000000
- 001f:Ret user32.DispatchMessageW() retval=00000000 ret=7ed95e90
- 001f:Call user32.GetMessageW(0033f6b8,00000000,00000000,00000000) ret=7ed95eb3
- 001f:Ret user32.GetMessageW() retval=00000000 ret=7ed95eb3
- 001f:Call KERNEL32.ExitProcess(00000000) ret=7ed95ed3
- 001f:Call PE DLL (proc=0x7e5714f0,module=0x7e4f0000 L"shell32.dll",reason=PROCESS_DETACH,res=0x1)
- 001f:Call comctl32.DPA_DestroyCallback(0013a488,7e51c3e0,00000000) ret=7e51d62c
- 001f:Call ntdll.RtlFreeHeap(00110000,00000000,0013c9c8) ret=7e51c419
- 001f:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e51c419
- 001f:Call KERNEL32.GetProcAddress(7e270000,7e596fc2 "CoTaskMemFree") ret=7e571411
- 001f:Ret KERNEL32.GetProcAddress() retval=7e279e70 ret=7e571411
- 001f:Call ole32.CoTaskMemFree(0013d4c0) ret=7e5351d9
- 001f:Call ntdll.RtlFreeHeap(00110000,00000000,0013d4c0) ret=7e2a59a8
- 001f:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e2a59a8
- 001f:Ret ole32.CoTaskMemFree() retval=00000000 ret=7e5351d9
- 001f:Call ntdll.RtlFreeHeap(00110000,00000000,0013ca30) ret=7e51c419
- 001f:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e51c419
- 001f:Call ole32.CoTaskMemFree(0013ca10) ret=7e5351d9
- 001f:Call ntdll.RtlFreeHeap(00110000,00000000,0013ca10) ret=7e2a59a8
- 001f:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e2a59a8
- 001f:Ret ole32.CoTaskMemFree() retval=00000000 ret=7e5351d9
- 001f:Call ntdll.RtlFreeHeap(00110000,00000000,0013b098) ret=7e3b524a
- 001f:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e3b524a
- 001f:Call ntdll.RtlFreeHeap(00110000,00000000,0013a488) ret=7e3b5268
- 001f:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e3b5268
- 001f:Ret comctl32.DPA_DestroyCallback() retval=00000001 ret=7e51d62c
- 001f:Call comctl32.ImageList_Destroy(0013b510) ret=7e51d649
- 001f:Call gdi32.DeleteObject(00000510) ret=7e3be17d
- 001f:Ret gdi32.DeleteObject() retval=00000001 ret=7e3be17d
- 001f:Call gdi32.DeleteObject(00000514) ret=7e3be18f
- 001f:Ret gdi32.DeleteObject() retval=00000001 ret=7e3be18f
- 001f:Call gdi32.DeleteDC(000002e0) ret=7e3be1a1
- 001f:Ret gdi32.DeleteDC() retval=00000001 ret=7e3be1a1
- 001f:Call gdi32.DeleteDC(000002ec) ret=7e3be1b3
- 001f:Ret gdi32.DeleteDC() retval=00000001 ret=7e3be1b3
- 001f:Call gdi32.DeleteObject(00000308) ret=7e3be1c5
- 001f:Ret gdi32.DeleteObject() retval=00000001 ret=7e3be1c5
- 001f:Call gdi32.DeleteObject(00000314) ret=7e3be1d7
- 001f:Ret gdi32.DeleteObject() retval=00000001 ret=7e3be1d7
- 001f:Call ntdll.RtlFreeHeap(00110000,00000000,0013bb10) ret=7e3be203
- 001f:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e3be203
- 001f:Call ntdll.RtlFreeHeap(00110000,00000000,0013b510) ret=7e3be223
- 001f:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e3be223
- 001f:Ret comctl32.ImageList_Destroy() retval=00000001 ret=7e51d649
- 001f:Call comctl32.ImageList_Destroy(0013bf68) ret=7e51d662
- 001f:Call gdi32.DeleteObject(000005ac) ret=7e3be17d
- 001f:Ret gdi32.DeleteObject() retval=00000001 ret=7e3be17d
- 001f:Call gdi32.DeleteObject(000005b0) ret=7e3be18f
- 001f:Ret gdi32.DeleteObject() retval=00000001 ret=7e3be18f
- 001f:Call gdi32.DeleteDC(00000318) ret=7e3be1a1
- 001f:Ret gdi32.DeleteDC() retval=00000001 ret=7e3be1a1
- 001f:Call gdi32.DeleteDC(00000324) ret=7e3be1b3
- 001f:Ret gdi32.DeleteDC() retval=00000001 ret=7e3be1b3
- 001f:Call gdi32.DeleteObject(00000340) ret=7e3be1c5
- 001f:Ret gdi32.DeleteObject() retval=00000001 ret=7e3be1c5
- 001f:Call gdi32.DeleteObject(0000034c) ret=7e3be1d7
- 001f:Ret gdi32.DeleteObject() retval=00000001 ret=7e3be1d7
- 001f:Call ntdll.RtlFreeHeap(00110000,00000000,0013c570) ret=7e3be203
- 001f:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e3be203
- 001f:Call ntdll.RtlFreeHeap(00110000,00000000,0013bf68) ret=7e3be223
- 001f:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e3be223
- 001f:Ret comctl32.ImageList_Destroy() retval=00000001 ret=7e51d662
- 001f:Call ntdll.RtlDeleteCriticalSection(7e6df3a0) ret=7e51d67e
- 001f:Ret ntdll.RtlDeleteCriticalSection() retval=00000000 ret=7e51d67e
- 001f:Call ntdll.RtlDeleteCriticalSection(7e6df248) ret=7e509600
- 001f:Ret ntdll.RtlDeleteCriticalSection() retval=00000000 ret=7e509600
- 001f:Call KERNEL32.FreeLibrary(7e270000) ret=7e5714d1
- 001f:Ret KERNEL32.FreeLibrary() retval=00000001 ret=7e5714d1
- 001f:Ret PE DLL (proc=0x7e5714f0,module=0x7e4f0000 L"shell32.dll",reason=PROCESS_DETACH,res=0x1) retval=1
- 001f:Call PE DLL (proc=0x7e333440,module=0x7e270000 L"ole32.dll",reason=PROCESS_DETACH,res=0x1)
- 001f:Call user32.UnregisterClassW(7e337600 L"OleMainThreadWndClass 0x######## ",7e270000) ret=7e290a0e
- 001f:Ret user32.UnregisterClassW() retval=00000001 ret=7e290a0e
- 001f:Ret PE DLL (proc=0x7e333440,module=0x7e270000 L"ole32.dll",reason=PROCESS_DETACH,res=0x1) retval=1
- 001f:Call PE DLL (proc=0x7e43a360,module=0x7e3a0000 L"comctl32.dll",reason=PROCESS_DETACH,res=0x1)
- 001f:Call user32.UnregisterClassW(0033f1e2 L"SysAnimate32",00000000) ret=7e3a6677
- 001f:Ret user32.UnregisterClassW() retval=00000001 ret=7e3a6677
- 001f:Call user32.UnregisterClassW(0033f1e2 L"ComboBoxEx32",00000000) ret=7e3ac497
- 001f:Ret user32.UnregisterClassW() retval=00000001 ret=7e3ac497
- 001f:Call user32.UnregisterClassW(0033f1d8 L"SysDateTimePick32",00000000) ret=7e3b4e25
- 001f:Ret user32.UnregisterClassW() retval=00000001 ret=7e3b4e25
- 001f:Call user32.UnregisterClassW(0033f1de L"flatsb_class32",00000000) ret=7e3b80b3
- 001f:Ret user32.UnregisterClassW() retval=00000001 ret=7e3b80b3
- 001f:Call user32.UnregisterClassW(0033f1e4 L"SysHeader32",00000000) ret=7e3bcb81
- 001f:Ret user32.UnregisterClassW() retval=00000001 ret=7e3bcb81
- 001f:Call user32.UnregisterClassW(0033f1dc L"msctls_hotkey32",00000000) ret=7e3bdee9
- 001f:Ret user32.UnregisterClassW() retval=00000001 ret=7e3bdee9
- 001f:Call user32.UnregisterClassW(0033f1de L"SysIPAddress32",00000000) ret=7e3c7b83
- 001f:Ret user32.UnregisterClassW() retval=00000001 ret=7e3c7b83
- 001f:Call user32.UnregisterClassW(0033f1e0 L"SysListView32",00000000) ret=7e3e2e8d
- 001f:Ret user32.UnregisterClassW() retval=00000001 ret=7e3e2e8d
- 001f:Call user32.UnregisterClassW(0033f1e0 L"SysMonthCal32",00000000) ret=7e3ea5bd
- 001f:Ret user32.UnregisterClassW() retval=00000001 ret=7e3ea5bd
- 001f:Call user32.UnregisterClassW(0033f1e0 L"NativeFontCtl",00000000) ret=7e3ea93d
- 001f:Ret user32.UnregisterClassW() retval=00000001 ret=7e3ea93d
- 001f:Call user32.UnregisterClassW(0033f1ea L"SysPager",00000000) ret=7e3ed7df
- 001f:Ret user32.UnregisterClassW() retval=00000001 ret=7e3ed7df
- 001f:Call user32.UnregisterClassW(0033f1d8 L"msctls_progress32",00000000) ret=7e3eefa5
- 001f:Ret user32.UnregisterClassW() retval=00000001 ret=7e3eefa5
- 001f:Call user32.UnregisterClassW(0033f1e0 L"ReBarWindow32",00000000) ret=7e4000dd
- 001f:Ret user32.UnregisterClassW() retval=00000001 ret=7e4000dd
- 001f:Call user32.UnregisterClassW(0033f1d6 L"msctls_statusbar32",00000000) ret=7e40368b
- 001f:Ret user32.UnregisterClassW() retval=00000001 ret=7e40368b
- 001f:Call user32.UnregisterClassW(0033f1ec L"SysLink",00000000) ret=7e407ef9
- 001f:Ret user32.UnregisterClassW() retval=00000001 ret=7e407ef9
- 001f:Call user32.UnregisterClassW(0033f1dc L"SysTabControl32",00000000) ret=7e40eee9
- 001f:Ret user32.UnregisterClassW() retval=00000001 ret=7e40eee9
- 001f:Call user32.UnregisterClassW(0033f1dc L"ToolbarWindow32",00000000) ret=7e421b49
- 001f:Ret user32.UnregisterClassW() retval=00000001 ret=7e421b49
- 001f:Call user32.DestroyIcon(0005003c) ret=7e426ab0
- 001f:Ret user32.DestroyIcon() retval=00000001 ret=7e426ab0
- 001f:Call user32.DestroyIcon(0001003e) ret=7e426ac1
- 001f:Ret user32.DestroyIcon() retval=00000001 ret=7e426ac1
- 001f:Call user32.DestroyIcon(00010040) ret=7e426ad2
- 001f:Ret user32.DestroyIcon() retval=00000001 ret=7e426ad2
- 001f:Call user32.UnregisterClassW(0033f1da L"tooltips_class32",00000000) ret=7e426b4e
- 001f:Ret user32.UnregisterClassW() retval=00000001 ret=7e426b4e
- 001f:Call user32.UnregisterClassW(0033f1d8 L"msctls_trackbar32",00000000) ret=7e42aaa5
- 001f:Ret user32.UnregisterClassW() retval=00000001 ret=7e42aaa5
- 001f:Call user32.UnregisterClassW(0033f1e0 L"SysTreeView32",00000000) ret=7e437ccd
- 001f:Ret user32.UnregisterClassW() retval=00000001 ret=7e437ccd
- 001f:Call user32.UnregisterClassW(0033f1dc L"msctls_updown32",00000000) ret=7e43a219
- 001f:Ret user32.UnregisterClassW() retval=00000001 ret=7e43a219
- 001f:Call gdi32.DeleteObject(00000270) ret=7e3b09c5
- 001f:Ret gdi32.DeleteObject() retval=00000001 ret=7e3b09c5
- 001f:Call gdi32.DeleteObject(00000268) ret=7e3b09dc
- 001f:Ret gdi32.DeleteObject() retval=00000001 ret=7e3b09dc
- 001f:Call KERNEL32.GlobalDeleteAtom(0000c016) ret=7e3b09f8
- 001f:Ret KERNEL32.GlobalDeleteAtom() retval=00000000 ret=7e3b09f8
- 001f:Call KERNEL32.FreeLibrary(7e360000) ret=7e43a341
- 001f:Ret KERNEL32.FreeLibrary() retval=00000001 ret=7e43a341
- 001f:Ret PE DLL (proc=0x7e43a360,module=0x7e3a0000 L"comctl32.dll",reason=PROCESS_DETACH,res=0x1) retval=1
- 001f:Call PE DLL (proc=0x7e379a90,module=0x7e360000 L"uxtheme.dll",reason=PROCESS_DETACH,res=0x1)
- 001f:Ret PE DLL (proc=0x7e379a90,module=0x7e360000 L"uxtheme.dll",reason=PROCESS_DETACH,res=0x1) retval=1
- 001f:Call PE DLL (proc=0x7e4ca840,module=0x7e490000 L"shlwapi.dll",reason=PROCESS_DETACH,res=0x1)
- 001f:Call KERNEL32.TlsFree(00000002) ret=7e4bcea2
- 001f:Ret KERNEL32.TlsFree() retval=00000001 ret=7e4bcea2
- 001f:Ret PE DLL (proc=0x7e4ca840,module=0x7e490000 L"shlwapi.dll",reason=PROCESS_DETACH,res=0x1) retval=1
- 001f:Call PE DLL (proc=0x7ec34910,module=0x7eb90000 L"user32.dll",reason=PROCESS_DETACH,res=0x1)
- 001f:Ret PE DLL (proc=0x7ec34910,module=0x7eb90000 L"user32.dll",reason=PROCESS_DETACH,res=0x1) retval=1
- 001f:Call PE DLL (proc=0x7e966a10,module=0x7e8f0000 L"winex11.drv",reason=PROCESS_DETACH,res=0x1)
- 001f:Ret PE DLL (proc=0x7e966a10,module=0x7e8f0000 L"winex11.drv",reason=PROCESS_DETACH,res=0x1) retval=1
- 001f:Call PE DLL (proc=0x7e75aef0,module=0x7e750000 L"imm32.dll",reason=PROCESS_DETACH,res=0x1)
- 001f:Call KERNEL32.TlsFree(00000000) ret=7e7592b5
- 001f:Ret KERNEL32.TlsFree() retval=00000001 ret=7e7592b5
- 001f:Ret PE DLL (proc=0x7e75aef0,module=0x7e750000 L"imm32.dll",reason=PROCESS_DETACH,res=0x1) retval=1
- 001f:Call PE DLL (proc=0x7eaf0ee0,module=0x7eae0000 L"version.dll",reason=PROCESS_DETACH,res=0x1)
- 001f:Ret PE DLL (proc=0x7eaf0ee0,module=0x7eae0000 L"version.dll",reason=PROCESS_DETACH,res=0x1) retval=1
- 001f:Call PE DLL (proc=0x7eb5c560,module=0x7eb00000 L"gdi32.dll",reason=PROCESS_DETACH,res=0x1)
- 001f:Ret PE DLL (proc=0x7eb5c560,module=0x7eb00000 L"gdi32.dll",reason=PROCESS_DETACH,res=0x1) retval=1
- 001f:Call PE DLL (proc=0x7ed6a050,module=0x7ed20000 L"rpcrt4.dll",reason=PROCESS_DETACH,res=0x1)
- 001f:Ret PE DLL (proc=0x7ed6a050,module=0x7ed20000 L"rpcrt4.dll",reason=PROCESS_DETACH,res=0x1) retval=1
- 001f:Call PE DLL (proc=0x7ecfe300,module=0x7ecc0000 L"advapi32.dll",reason=PROCESS_DETACH,res=0x1)
- 001f:Ret PE DLL (proc=0x7ecfe300,module=0x7ecc0000 L"advapi32.dll",reason=PROCESS_DETACH,res=0x1) retval=1
- 001f:Call PE DLL (proc=0x7b8790f0,module=0x7b810000 L"KERNEL32.dll",reason=PROCESS_DETACH,res=0x1)
- 001f:Ret PE DLL (proc=0x7b8790f0,module=0x7b810000 L"KERNEL32.dll",reason=PROCESS_DETACH,res=0x1) retval=1
- 001f:Call PE DLL (proc=0x7bc88ea0,module=0x7bc10000 L"ntdll.dll",reason=PROCESS_DETACH,res=0x1)
- 001f:Ret PE DLL (proc=0x7bc88ea0,module=0x7bc10000 L"ntdll.dll",reason=PROCESS_DETACH,res=0x1) retval=1
- 0012:Call PE DLL (proc=0x7eccd050,module=0x7ec80000 L"rpcrt4.dll",reason=PROCESS_DETACH,res=0x1)
- 001a:Ret PE DLL (proc=0x7ed14050,module=0x7ecd0000 L"rpcrt4.dll",reason=PROCESS_DETACH,res=0x1) retval=1
- 0012:Ret PE DLL (proc=0x7eccd050,module=0x7ec80000 L"rpcrt4.dll",reason=PROCESS_DETACH,res=0x1) re001a:Re0012:Call PE DLL (proc=0x7ed0a470,module=0x7ecf0000 L"ntoskrnl.exe",reason=PROCESS_DETACH,res=0x1)
- 001a:Call PE DLL (proc=0x7b8790f0,module=0x7b810000 L"KERNEL32.dll",reason=PROCESS_DETACH,res=0x1)
- 001a:Ret PE DLL (proc=0x7b8790f0,module=0x7b810000 L"KERNEL32.dll",reaso0012:Ret ntdll.RtlRemoveVectoredEx001a:Call PE DLL (proc=0x7bc88ea0,module=0x7bc0012:Ret PE DLL (proc=0x7ed0a470,module=0x7ecf000001a:Ret PE DLL (proc=0x7bc88ea0,module=0x7bc10000 L"ntdl0012:Call PE DLL (proc=0x7ed76300,module=0x7ed40000 L"advapi32.dll",reason=PROCESS_DETACH,res=0x1)
- 0012:Ret PE DLL (proc=0x7ed76300,module=0x7ed40000 L"advapi32.dll",reason=PROCESS_DETACH,res=0x1) retval=1
- 0012:Call PE DLL (proc=0x7b8790f0,module=0x7b810000 L"KERNEL32.dll",reason=PROCESS_DETACH,res=0x1)
- 0028:Ret KERNEL32.WaitForSingleObject() retval=00000000 ret=7eda194f
- 0028:Call rpcrt4.RpcMgmtStopServerListening(00000000) ret=7eda195e
- 0028:Call KERNEL32.WaitForSingleObject(0000003c,ffffffff) ret=7ed65dcc
- 000f:Ret KERNEL32.WaitForSingleObjectEx() retval=00000000 ret=7ed9a61c
- 000f:Call KERNEL32.CloseHandle(00000070) ret=7ed9a694
- 000f:Ret KERNEL32.CloseHandle() retval=00000001 ret=7ed9a694
- 000f:Call advapi32.RegCloseKey(0000001c) ret=7ed9c7c0
- 000f:Ret advapi32.RegCloseKey() retval=00000000 ret=7ed9c7c0
- 0028:Ret KERNEL32.WaitForSingleObject() retval=00000000 ret=7ed000f:R0028:Call KERNEL32.SetEvent(00000028) ret=7ed6b314
- 000f:Call ntdll.RtlFreeHeap(00110000,00000000,001150b0) ret=7ed9c7ee
- 000f:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed9c7ee
- 000f:Call KERNEL32.ExitProcess(00000000) ret=7eda4297
- 000f:Call PE DLL (proc=0x7ed6b050,module=0x7ed20000 L"rpcrt4.dll",reason=PROCESS_DETACH,res=0x1)
- 000f:Call KERNEL32.WaitForSingleObject(0000002c,ffffffff) ret=7ed5bdcc
- 0029:Ret KERNEL32.WaitForMultipleObjectsEx() retval=00000000 ret=7ed7038f
- 0029:Call ntdll.RtlFreeHeap(00110000,00000000,00117280) ret=7ed6ac46
- 0029:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed6ac46
- 0029:Call KERNEL32.FlushFileBuffers(00000050) ret=7ed6f4d9
- 0028:Ret KERNEL32.SetEvent() retval=00000001 ret=7ed6b314
- 0028:Call KERNEL32.WaitForSingleObject(00000040,ffffffff) ret=7ed65dea
- 001c:Ret KERNEL32.ReadFile() retval=00000000 ret=7ed655dd
- 001c:Call ntdll.RtlFreeHeap(00110000,00000000,00000000) ret=7ed589c6
- 001c:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed589c6
- 001c:Call ntdll.RtlFreeHeap(00110000,00000000,00000000) ret=7ed5a697
- 001c:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed5a697
- 001c:Call ntdll.RtlFreeHeap(00110000,00000000,00000000) ret=7ed68c46
- 001c:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed68c46
- 001c:Call ntdll.RtlFreeHeap(00110000,00000000,00000000) ret=7ed589c6
- 001c:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed589c6
- 001c:Call ntdll.RtlFreeHeap(00110000,00000000,00000000) ret=7ed5ad85
- 001c:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed5ad85
- 001c:Call ntdll.RtlFreeHeap(00110000,00000000,00000000) ret=7ed5aa43
- 001c:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed5aa43
- 001c:Call ntdll.RtlFreeHeap(00110000,00000000,00118828) ret=7ed5db34
- 001c:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed5db34
- 001c:Call KERNEL32.FlushFileBuffers(00000044) ret=7ed654d9
- 000f:Ret KERNEL32.WaitForSingleObject() retval=00000000 ret=7ed5bdcc
- 000f:Call KERNEL32.SetEvent(00000020) ret=7ed61314
- 0029:Ret KERNEL32.FlushFileBuffers() retval=00000001 ret=7ed6f4d9
- 0029:Call KERNEL32.CloseHandle(00000050) ret=7ed6f4e7
- 0014:Ret KERNEL32.ReadFile() retval=00000000 ret=7ed655dd
- 0014:Call ntdll.RtlFreeHeap(00110000,00000000,00000000) ret=7ed589c6
- 0014:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed589c6
- 0014:Call ntdll.RtlFreeHeap(00110000,00000000,00000000) ret=7ed5a697
- 0014:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed5a697
- 0014:Call ntdll.RtlFreeHeap(00110000,00000000,00000000) ret=7ed68c46
- 0014:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed68c46
- 0014:Call ntdll.RtlFreeHeap(00110000,00000000,00000000) ret=7ed589c6
- 0014:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed589c6
- 0014:Call ntdll.RtlFreeHeap(00110000,00000000,00000000) ret=7ed5ad85
- 0014:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed5ad85
- 0014:Call ntdll.RtlFreeHeap(00110000,00000000,00000000) ret=7ed5aa43
- 0014:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed5aa43
- 0014:Call ntdll.RtlFreeHeap(00110000,00000000,001182d8) ret=7ed5db34
- 0014:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed5db34
- 0014:Call KERNEL32.FlushFileBuffers(00000024) ret=7ed654d9
- 0010:Ret KERNEL32.WaitForMultipleObjectsEx() retval=00000000 ret=7ed6638f
- 0010:Call ntdll.RtlFreeHeap(00110000,00000000,00117d70) ret=7ed60c46
- 0010:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed60c46
- 0010:Call KERNEL32.FlushFileBuffers(0000006c) ret=7ed654d9
- 001c:Ret KERNEL32.FlushFileBuffers() retval=00000001 ret=7ed654d9
- 001c:Call KERNEL32.CloseHandle(00000044) ret=7ed654e7
- 000f:Ret KERNEL32.SetEvent() retval=00000001 ret=7ed61314
- 000f:Call KERNEL32.WaitForSingleObject(00000030,ffffffff) ret=7ed5bdea
- 0014:Ret KERNEL32.FlushFileBuffers() retval=00000001 ret=7ed654d9
- 0014:Call KERNEL32.CloseHandle(00000024) ret=7ed654e7
- 0010:Ret KERNEL32.FlushFileBuffers() retval=00000001 ret=7ed654d9
- 001c:Ret KERNEL32.CloseHandle() retval=00000001 ret=7ed654e7
- 001c:Call KERNEL32.CloseHandle(0000004c) ret=7ed65503
- 0014:Ret KERNEL32.CloseHandle() retval=00000001 ret=7ed654e7
- 001c:Ret KERNEL32.CloseHandle() retval=00000001 ret=7ed65503
- 001c:Call ntdll.RtlFreeHeap(00110000,00000000,00117f08) ret=7ed51576
- 001c:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed51576
- 001c:Call ntdll.RtlFreeHeap(00110000,00000000,00000000) ret=7ed51576
- 001c:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed51576
- 001c:Call ntdll.RtlFreeHeap(00110000,00000000,00000000) ret=7ed667d1
- 001c:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed667d1
- 001c:Call ntdll.RtlFreeHeap(00110000,00000000,00118810) ret=7ed97497
- 001c:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed97497
- 001c:Call ntdll.RtlDeleteResource(001187b4) ret=7ed4f098
- 0014:Ret KERNEL32.CloseHandle() retval=00000001 ret=7ed65503
- 0014:Call ntdll.RtlFreeHeap(00110000,00000000,00118068) ret=7ed51576
- 0014:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed51576
- 0014:Call ntdll.RtlFreeHeap(00110000,00000000,00000000) ret=7ed51576
- 0014:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed51576
- 0014:Call ntdll.RtlFreeHeap(00110000,00000000,00000000) ret=7ed667d1
- 001c:Ret ntdll.RtlDeleteResource() retval=00000000 ret=7ed0014:C001c:Call ntdll.RtlFreeHeap(00110000,00000000,00118790) ret=7ed0014:R001c:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed0014:C001c:Call ntdll.RtlFreeHeap(00110000,00000000,00118968) ret=7ed97497
- 001c:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed97497
- 001c:Call ntdll.RtlDeleteResource(0011890c) ret=7ed4f098
- 0014:Ret ntdll.RtlDeleteResource() retval=00000000 ret=7ed4f098
- 0014:Call ntdll.RtlFreeHeap(00110000,00000000,00118348) ret=7ed4f0b8
- 0014:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed4f0b8
- 0014:Call ntdll.RtlFreeHeap(00110000,00000000,001183d8) ret=7ed97497
- 0014:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed97497
- 0014:Call ntdll.RtlDeleteResource(0011842c) ret=7ed4f098
- 0029:Ret KERNEL32.CloseHandle() retval=00000001 ret=7ed6f503
- 0029:Call KERNEL32.FlushFileBuffers(0000002c) ret=7ed6f4d9
- 001c:Ret ntdll.RtlDeleteResource() retval=00000000 ret=7ed4f098
- 001c:Call ntdll.RtlFreeHeap(00110000,00000000,001188e8) ret=7ed4f0b8
- 001c:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed4f0b8
- 001c:Call ntdll.RtlFreeHeap(00110000,00000000,00000000) ret=7ed4f74a
- 001c:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed4f74a
- 001c:Call ntdll.RtlFreeHeap(00110000,00000000,00118740) ret=7ed4f76d
- 001c:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed4f76d
- 001c:Call ntdll.RtlFreeHeap(00110000,00000000,00000000) ret=7ed4f790
- 001c:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed4f790
- 001c:Call ntdll.RtlFreeHeap(00110000,00000000,00118728) ret=7ed4f7b3
- 001c:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed4f7b3
- 001c:Call ntdll.RtlDeleteCriticalSection(001186d0) ret=7ed4f7c1
- 001c:Ret ntdll.RtlDeleteCriticalSection() retval=00000000 ret=7ed4f7c1
- 001c:Call ntdll.RtlFreeHeap(00110000,00000000,001186a0) ret=7ed4f7e1
- 001c:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed4f7e1
- 001c:Call ntdll.RtlFreeHeap(00110000,00000000,001185f8) ret=7ed51576
- 001c:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed51576
- 001c:Call ntdll.RtlFreeHeap(00110000,00000000,00000000) ret=7ed51576
- 001c:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed51576
- 001c:Call ntdll.RtlFreeHeap(00110000,00000000,001185e0) ret=7ed51576
- 001c:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed51576
- 001c:Call ntdll.RtlFreeHeap(00110000,00000000,00000000) ret=7ed53d2d
- 001c:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed53d2d
- 001c:Call ntdll.RtlFreeHeap(00110000,00000000,00118650) ret=7ed53d6b
- 001c:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed53d6b
- 001c:Call ntdll.RtlFreeHeap(00110000,00000000,00118488) ret=7ed6681e
- 001c:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed6681e
- 0010:Ret KERNEL32.CloseHandle() retval=00000001 ret=7ed654e7
- 0010:Call KERNEL32.CloseHandle(00000074) ret=7ed65503
- 0029:Ret KERNEL32.FlushFileBuffers() retval=00000001 ret=7ed6f4d9
- 0029:Call KERNEL32.CloseHandle(0000002c) ret=7ed6f4e7
- 0014:Ret ntdll.RtlDeleteResource() retval=00000000 ret=7ed4f098
- 0014:Call ntdll.RtlFreeHeap(00110000,00000000,00118408) ret=7ed4f0b8
- 0014:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed4f0b8
- 0014:Call ntdll.RtlFreeHeap(00110000,00000000,00000000) ret=7ed4f74a
- 0014:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed4f74a
- 0014:Call ntdll.RtlFreeHeap(00110000,00000000,001182c0) ret=7ed4f76d
- 0014:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed4f76d
- 0014:Call ntdll.RtlFreeHeap(00110000,00000000,00000000) ret=7ed4f790
- 0014:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed4f790
- 0014:Call ntdll.RtlFreeHeap(00110000,00000000,001182a8) ret=7ed4f7b3
- 0014:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed4f7b3
- 0014:Call ntdll.RtlDeleteCriticalSection(00118250) ret=7ed4f7c1
- 0014:Ret ntdll.RtlDeleteCriticalSection() retval=00000000 ret=7ed4f7c1
- 0014:Call ntdll.RtlFreeHeap(00110000,00000000,00118220) ret=7ed4f7e1
- 0014:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed4f7e1
- 0014:Call ntdll.RtlFreeHeap(00110000,00000000,00118178) ret=7ed51576
- 0014:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed51576
- 0014:Call ntdll.RtlFreeHeap(00110000,00000000,00000000) ret=7ed51576
- 0014:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed51576
- 0014:Call ntdll.RtlFreeHeap(00110000,00000000,00118160) ret=7ed51576
- 0014:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed51576
- 0014:Call ntdll.RtlFreeHeap(00110000,00000000,00000000) ret=7ed53d2d
- 0014:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed53d2d
- 0014:Call ntdll.RtlFreeHeap(00110000,00000000,001181d0) ret=7ed53d6b
- 0014:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed53d6b
- 0014:Call ntdll.RtlFreeHeap(00110000,00000000,00117fd0) ret=7ed6681e
- 0014:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed6681e
- 0010:Ret KERNEL32.CloseHandle() retval=00000001 ret=7ed65503
- 0010:Call KERNEL32.SetEvent(00000030) ret=7ed5bf63
- 0010:Ret KERNEL32.SetEvent() retval=00000001 ret=7ed5bf63
- 000f:Ret KERNEL32.WaitForSingleObject() retval=00000000 ret=7ed5bdea
- 000f:Call KERNEL32.ReleaseMutex(0000002c) ret=7ed5bdf8
- 000f:Ret KERNEL32.ReleaseMutex() retval=00000001 ret=7ed5bdf8
- 000f:Call ntdll.RtlFreeHeap(00110000,00000000,00117dd0) ret=7ed51576
- 000f:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed51576
- 000f:Call ntdll.RtlDeleteCriticalSection(00117da0) ret=7ed5e706
- 000f:Ret ntdll.RtlDeleteCriticalSection() retval=00000000 ret=7ed5e706
- 000f:Call KERNEL32.CloseHandle(0000002c) ret=7ed5e714
- 000f:Ret KERNEL32.CloseHandle() retval=00000001 ret=7ed5e714
- 000f:Call KERNEL32.CloseHandle(00000030) ret=7ed5e722
- 000f:Ret KERNEL32.CloseHandle() retval=00000001 ret=7ed5e722
- 000f:Call ntdll.RtlFreeHeap(00110000,00000000,00117d88) ret=7ed5e753
- 000f:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed5e753
- 000f:Ret PE DLL (proc=0x7ed6b050,module=0x7ed20000 L"rpcrt4.dll",reason=PROCESS_DETACH,res=0x1) retval=1
- 000f:Call PE DLL (proc=0x7ecff300,module=0x7ecc0000 L"advapi32.dll",reason=PROCESS_DETACH,res=0x1)
- 000f:Ret PE DLL (proc=0x7ecff300,module=0x7ecc0000 L"advapi32.dll",reason=PROCESS_DETACH,res=0x1) retval=1
- 000f:Call PE DLL (proc=0x7b8790f0,module=0x7b810000 L"KERNEL32.dll",reason=PROCESS_DETACH,res=0x1)
- 000f:Ret PE DLL (proc=0x7b8790f0,module=0x7b810000 L"KERNEL32.dll",reason=PROCESS_DETACH,res=0x1) retval=1
- 000f:Call PE DLL (proc=0x7bc88ea0,module=0x7bc10000 L"ntdll.dll",reason=PROCESS_DETACH,res=0x1)
- 000f:Ret PE DLL (proc=0x7bc88ea0,module=0x7bc10000 L"ntdll.dll",reason=PROCESS_DETACH,res=0x1) retval=1
- 0029:Ret KERNEL32.CloseHandle() retval=00000001 ret=7ed6f4e7
- 0029:Call KERNEL32.CloseHandle(00000030) ret=7ed6f503
- 0029:Ret KERNEL32.CloseHandle() retval=00000001 ret=7ed6f503
- 0029:Call KERNEL32.SetEvent(00000040) ret=7ed65f63
- 0028:Ret KERNEL32.WaitForSingleObject() retval=00000000 ret=7ed65dea
- 0028:Call KERNEL32.ReleaseMutex(0000003c) ret=7ed65df8
- 0028:Ret KERNEL32.ReleaseMutex() retval=00000001 ret=7ed65df8
- 0028:Call KERNEL32.WaitForSingleObject(00000044,ffffffff) ret=7ed65dcc
- 0028:Ret KERNEL32.WaitForSingleObject() retval=00000000 ret=7ed65dcc
- 0028:Call KERNEL32.SetEvent(00000018) ret=7ed6b314
- 0028:Ret KERNEL32.SetEvent() retval=00000001 ret=7ed6b314
- 0028:Call KERNEL32.WaitForSingleObject(00000048,ffffffff) ret=7ed65dea
- 0029:Ret KERNEL32.SetEvent() retval=00000001 ret=7ed65f63
- 0029:Call PE DLL (proc=0x7ed75050,module=0x7ed30000 L"rpcrt4.dll",rea002a:Ret ntdll.RtlFreeHeap()0029:Ret PE DLL (proc=0x7ed75002a:Call KERNEL32.FlushFileBuffers(00000020) ret=7ed6f4d9
- 002a:Ret KERNEL32.FlushFileBuffers() retval=00000001 ret=7ed6f4d9
- 002a:Call KERNEL32.CloseHandle(00000020) ret=7ed6f4e7
- 002a:Ret KERNEL32.CloseHandle() retval=00000001 ret=7ed6f4e7
- 002a:Call KERNEL32.CloseHandle(00000024) ret=7ed6f503
- 002a:Ret KERNEL32.CloseHandle() retval=00000001 ret=7ed6f503
- 002a:Call KERNEL32.SetEvent(00000048) ret=7ed65f63
- 0028:Ret KERNEL32.WaitForSingleObject() retval=00000000 ret=7ed65dea
- 0028:Call KERNEL32.ReleaseMutex(00000044) ret=7ed65df8
- 002a:Ret KERNEL32.SetEvent() retval=00000001 ret=7ed65f63
- 002a:Call PE DLL (proc=0x7ed75050,module=0x7ed30000 L"rpcrt4.dll",reason=THREAD_DETACH,res=(nil))
- 002a:Ret PE DLL (proc=0x7ed75050,module=0x7ed30000 L"rpcrt4.dll",reason=THREAD_DETACH,res=(nil)) retval=1
- 0028:Ret KERNEL32.ReleaseMutex() retval=00000001 ret=7ed65df8
- 0028:Ret rpcrt4.RpcMgmtStopServerListening() retval=00000000 ret=7eda195e
- 0028:Call rpcrt4.RpcServerUnregisterIf(7eda6d00,00000000,00000001) ret=7eda197b
- 0028:Call ntdll.RtlFreeHeap(00110000,00000000,00115148) ret=7ed693a9
- 0028:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed693a9
- 0028:Ret rpcrt4.RpcServerUnregisterIf() retval=00000000 ret=7eda197b
- 0028:Call rpcrt4.RpcServerUnregisterIf(7eda6d80,00000000,00000001) ret=7eda1998
- 0028:Call ntdll.RtlFreeHeap(00110000,00000000,00115190) ret=7ed693a9
- 0028:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed693a9
- 0028:Ret rpcrt4.RpcServerUnregisterIf() retval=00000000 ret=7eda1998
- 0028:Call KERNEL32.CloseHandle(0000004c) ret=7eda19a9
- 0028:Ret KERNEL32.CloseHandle() retval=00000001 ret=7eda19a9
- 0028:Call KERNEL32.ExitProcess(00000000) ret=7eda5067
- 0028:Call PE DLL (proc=0x7ed75050,module=0x7ed30000 L"rpcrt4.dll",reason=PROCESS_DETACH,res=0x1)
- 0028:Call ntdll.RtlFreeHeap(00110000,00000000,00117418) ret=7ed5b576
- 0028:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed5b576
- 0028:Call ntdll.RtlDeleteCriticalSection(001173e8) ret=7ed68706
- 0028:Ret ntdll.RtlDeleteCriticalSection() retval=00000000 ret=7ed68706
- 0028:Call KERNEL32.CloseHandle(0000003c) ret=7ed68714
- 0028:Ret KERNEL32.CloseHandle() retval=00000001 ret=7ed68714
- 0028:Call KERNEL32.CloseHandle(00000040) ret=7ed68722
- 0028:Ret KERNEL32.CloseHandle() retval=00000001 ret=7ed68722
- 0028:Call ntdll.RtlFreeHeap(00110000,00000000,001173d0) ret=7ed68753
- 0028:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed68753
- 0028:Call ntdll.RtlFreeHeap(00110000,00000000,001172e0) ret=7ed5b576
- 0028:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed5b576
- 0028:Call ntdll.RtlDeleteCriticalSection(001172b0) ret=7ed68706
- 0028:Ret ntdll.RtlDeleteCriticalSection() retval=00000000 ret=7ed68706
- 0028:Call KERNEL32.CloseHandle(00000044) ret=7ed68714
- 0028:Ret KERNEL32.CloseHandle() retval=00000001 ret=7ed68714
- 0028:Call KERNEL32.CloseHandle(00000048) ret=7ed68722
- 0028:Ret KERNEL32.CloseHandle() retval=00000001 ret=7ed68722
- 0028:Call ntdll.RtlFreeHeap(00110000,00000000,00117298) ret=7ed68753
- 0028:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed68753
- 0028:Ret PE DLL (proc=0x7ed75050,module=0x7ed30000 L"rpcrt4.dll",reason=PROCESS_DETACH,res=0x1) retval=1
- 0028:Call PE DLL (proc=0x7ed09300,module=0x7ecd0000 L"advapi32.dll",reason=PROCESS_DETACH,res=0x1)
- 0028:Ret PE DLL (proc=0x7ed09300,module=0x7ecd0000 L"advapi32.dll",reason=PROCESS_DETACH,res=0x1) retval=1
- 0028:Call PE DLL (proc=0x7b8790f0,module=0x7b810000 L"KERNEL32.dll",reason=PROCESS_DETACH,res=0x1)
- 0028:Ret PE DLL (proc=0x7b8790f0,module=0x7b810000 L"KERNEL32.dll",reason=PROCESS_DETACH,res=0x1) retval=1
- 0028:Call PE DLL (proc=0x7bc88ea0,module=0x7bc10000 L"ntdll.dll",reason=PROCESS_DETACH,res=0x1)
- 0028:Ret PE DLL (proc=0x7bc88ea0,module=0x7bc10000 L"ntdll.dll",reason=PROCESS_DETACH,res=0x1) retval=1
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement