Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Calls
- Screenshots
- Select call methods...
- Select processes...
- Select call types...
- Clear Filters
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"SetDefaultDllDirectories","hModule":"kernel32.dll"}
- Returned value:
- 0x0
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Windows\\system32\\UXTHEME.dll"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18fa6c","objectName":"\\??\\C:\\Windows\\system32\\UXTHEME.dll"}
- Returned value:
- null
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Windows\\system32\\USERENV.dll"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18fa6c","objectName":"\\??\\C:\\Windows\\system32\\USERENV.dll"}
- Returned value:
- null
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\Downloads\\profapi.dll"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Windows\\system32\\profapi.dll"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f6cc","objectName":"\\??\\C:\\Windows\\system32\\profapi.dll"}
- Returned value:
- null
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Windows\\system32\\SETUPAPI.dll"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18fa6c","objectName":"\\??\\C:\\Windows\\system32\\SETUPAPI.dll"}
- Returned value:
- null
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18f8e0","objectName":"SOFTWARE\\Microsoft\\OLEAUT","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18f910","objectName":"SOFTWARE\\Microsoft\\OLEAUT","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKey #native (#2236) important_document.exe
- Arguments:
- {"DesiredAccess":"0x1","KeyHandle":"0x18f194","objectName":"\\Registry\\Machine\\Software\\Microsoft\\Windows\\Windows Error Reporting\\WMR"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18f5d4","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Setup","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- KernelBase.dll! LoadLibraryExW #misc (#2236) important_document.exe
- Arguments:
- {"lpFileName":"API-MS-Win-Core-LocalRegistry-L1-1-0.dll"}
- Returned value:
- 0x773d0000
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"RegQueryValueExW","hModule":"kernel32.dll"}
- Returned value:
- 0x773e1f4e
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18f5b4","objectName":"Software\\Microsoft\\Windows\\CurrentVersion","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- KernelBase.dll! CreateMutexW #sync (#2236) important_document.exe
- Arguments:
- {"lpName":null}
- Returned value:
- 0x16c
- KernelBase.dll! CreateMutexW #sync (#2236) important_document.exe
- Arguments:
- {"lpName":null}
- Returned value:
- 0x174
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Windows\\system32\\VERSION.dll"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18fa5c","objectName":"\\??\\C:\\Windows\\system32\\VERSION.dll"}
- Returned value:
- null
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"GetFileVersionInfoA","hModule":"version.dll"}
- Returned value:
- 0x74801ced
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Windows\\system32\\SHFOLDER.dll"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18fa5c","objectName":"\\??\\C:\\Windows\\system32\\SHFOLDER.dll"}
- Returned value:
- null
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"SHGetFolderPathA","hModule":"shfolder.dll"}
- Returned value:
- 0x741f1528
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Windows\\system32\\rpcss.dll"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Windows\\system32\\rpcss.dll"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18fb2c","objectName":"\\Device\\KsecDD"}
- Returned value:
- null
- KernelBase.dll! LoadLibraryExA #misc (#2236) important_document.exe
- Arguments:
- {"lpFileName":"ole32.dll"}
- Returned value:
- 0x75720000
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"CoTaskMemAlloc","hModule":"ole32.dll"}
- Returned value:
- 0x7576ea4c
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ef64","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer","DesiredAccess":"0x1"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKey #native (#2236) important_document.exe
- Arguments:
- {"DesiredAccess":"0x2000000","KeyHandle":"0x774b0718","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ef64","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ef64","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer","DesiredAccess":"0x1"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ef64","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ef40","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer","DesiredAccess":"0x1"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ef40","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ef40","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer","DesiredAccess":"0x1"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ef40","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ef5c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer","DesiredAccess":"0x1"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ef5c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ef44","objectName":"SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\ShellCompatibility\\Applications\\important_document.exe","DesiredAccess":"0x9"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKey #native (#2236) important_document.exe
- Arguments:
- {"DesiredAccess":"0x20019","KeyHandle":"0x18e584","objectName":"\\Registry\\MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\SideBySide"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18e760","objectName":"\\??\\C:\\Windows\\syswow64\\SHELL32.dll"}
- Returned value:
- null
- ntdll.dll! NtOpenKey #native (#2236) important_document.exe
- Arguments:
- {"DesiredAccess":"0x8","KeyHandle":"0x18e2fc","objectName":"\\Registry\\Machine\\Software\\Microsoft\\Windows\\CurrentVersion\\SideBySide\\AssemblyStorageRoots"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\Downloads\\important_document.exe.Local\\"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18e2fc","objectName":"\\??\\C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2"}
- Returned value:
- null
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ef64","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer","DesiredAccess":"0x1"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ef64","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKey #native (#2236) important_document.exe
- Arguments:
- {"DesiredAccess":"0x2000000","KeyHandle":"0x774b0708","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18f13c","objectName":"CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18f13c","objectName":"\\Registry\\Machine\\Software\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder","DesiredAccess":"0x1"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ef4c","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder","DesiredAccess":"0x2000000"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ef4c","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder","DesiredAccess":"0x2000000"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ef4c","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder","DesiredAccess":"0x2000000"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ef4c","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder","DesiredAccess":"0x2000000"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ef4c","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder","DesiredAccess":"0x2000000"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ef4c","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder","DesiredAccess":"0x2000000"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ef4c","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder","DesiredAccess":"0x2000000"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ef4c","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder","DesiredAccess":"0x2000000"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ef4c","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder","DesiredAccess":"0x2000000"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ef4c","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder","DesiredAccess":"0x2000000"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ef4c","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder","DesiredAccess":"0x2000000"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ef4c","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder","DesiredAccess":"0x2000000"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ef4c","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder","DesiredAccess":"0x2000000"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ef4c","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder","DesiredAccess":"0x2000000"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ef4c","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder","DesiredAccess":"0x2000000"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ef4c","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder","DesiredAccess":"0x2000000"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ef4c","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder","DesiredAccess":"0x2000000"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ef4c","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder","DesiredAccess":"0x2000000"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18f0dc","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18f0dc","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18f070","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\NonEnum","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18f070","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\NonEnum","DesiredAccess":"0x1"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f0bc","objectName":"\\??\\C:"}
- Returned value:
- null
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f050","objectName":"\\??\\MountPointManager"}
- Returned value:
- null
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18f074","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18f290","objectName":"{e9b1a4f8-a98b-11e9-a299-806e6f6e6963}\\","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18f04c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18f268","objectName":"{e9b1a4f8-a98b-11e9-a299-806e6f6e6963}\\","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18f0f0","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18f30c","objectName":"{e9b1a4f8-a98b-11e9-a299-806e6f6e6963}\\","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18f398","objectName":"Drive\\shellex\\FolderExtensions","DesiredAccess":"0x8"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18f398","objectName":"\\Registry\\Machine\\Software\\Classes\\Drive\\shellex\\FolderExtensions","DesiredAccess":"0x8"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7ded64","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Drive\\shellex\\FolderExtensions","DesiredAccess":"0x2000000"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18f0fc","objectName":"Drive\\shellex\\FolderExtensions\\{fbeb8a05-beee-4442-804e-409d6c4515e9}","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18f0fc","objectName":"\\Registry\\Machine\\Software\\Classes\\Drive\\shellex\\FolderExtensions\\{fbeb8a05-beee-4442-804e-409d6c4515e9}","DesiredAccess":"0x1"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ef64","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Drive\\shellex\\FolderExtensions\\{fbeb8a05-beee-4442-804e-409d6c4515e9}","DesiredAccess":"0x2000000"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ddfc","objectName":"Software\\Policies\\Microsoft\\Windows\\Explorer","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ddfc","objectName":"Software\\Policies\\Microsoft\\Windows\\Explorer","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18e074","objectName":"\\??\\C:\\"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x3","dwFlagsAndAttributes":"0x2000000","lpFileName":"C:\\","dwDesiredAccess":"0x100081","dwShareMode":"0x7"}
- Returned value:
- 0x198
- ntdll.dll! NtOpenKey #native (#2236) important_document.exe
- Arguments:
- {"DesiredAccess":"0x2000000","KeyHandle":"0x18e364","objectName":"\\Registry\\User\\S-1-5-21-364843204-231886559-199882026-1001_Classes"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x31df940","objectName":"\\??\\STORAGE#Volume#{e9b1a4f4-a98b-11e9-a299-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"}
- Returned value:
- null
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x31dfb38","objectName":"\\??\\STORAGE#Volume#{e9b1a4f4-a98b-11e9-a299-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"}
- Returned value:
- null
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x31dfacc","objectName":"\\??\\MountPointManager"}
- Returned value:
- null
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x309f838","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x309fa54","objectName":"{e9b1a4f7-a98b-11e9-a299-806e6f6e6963}\\","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x309f810","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x309fa2c","objectName":"{e9b1a4f7-a98b-11e9-a299-806e6f6e6963}\\","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x31df940","objectName":"\\??\\STORAGE#Volume#{e9b1a4f4-a98b-11e9-a299-806e6f6e6963}#0000000006500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"}
- Returned value:
- null
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x31dfb38","objectName":"\\??\\STORAGE#Volume#{e9b1a4f4-a98b-11e9-a299-806e6f6e6963}#0000000006500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"}
- Returned value:
- null
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e384","objectName":"Software\\Microsoft\\COM3","DesiredAccess":"0x20119"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x31dfacc","objectName":"\\??\\MountPointManager"}
- Returned value:
- null
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x309f838","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x309fa54","objectName":"{e9b1a4f8-a98b-11e9-a299-806e6f6e6963}\\","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x309f810","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x309fa2c","objectName":"{e9b1a4f8-a98b-11e9-a299-806e6f6e6963}\\","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e1c8","objectName":"CLSID\\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e1c8","objectName":"\\Registry\\Machine\\Software\\Classes\\CLSID\\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x309fd04","objectName":"\\??\\MountPointManager"}
- Returned value:
- null
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x309fd04","objectName":"\\??\\MountPointManager"}
- Returned value:
- null
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x309fd04","objectName":"\\??\\MountPointManager"}
- Returned value:
- null
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x309fd04","objectName":"\\??\\MountPointManager"}
- Returned value:
- null
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x309fd04","objectName":"\\??\\MountPointManager"}
- Returned value:
- null
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x309fd04","objectName":"\\??\\MountPointManager"}
- Returned value:
- null
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e16c","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Wow6432Node\\CLSID\\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\\TreatAs","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e16c","objectName":"TreatAs","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e0c4","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Wow6432Node\\CLSID\\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\\Progid","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e0c4","objectName":"Progid","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e12c","objectName":"CLSID\\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}","DesiredAccess":"0x20119"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e12c","objectName":"\\Registry\\Machine\\Software\\Classes\\CLSID\\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}","DesiredAccess":"0x20119"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e0c4","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\CLSID\\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\\Progid","DesiredAccess":"0x101"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e0c4","objectName":"Progid","DesiredAccess":"0x101"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18df48","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Wow6432Node\\CLSID\\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}","DesiredAccess":"0x2000000"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18df48","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Wow6432Node\\CLSID\\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}","DesiredAccess":"0x2000000"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e100","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Wow6432Node\\CLSID\\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\\InprocServer32","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e100","objectName":"InprocServer32","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18defc","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Wow6432Node\\CLSID\\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\\InProcServer32","DesiredAccess":"0x2000000"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18df20","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Wow6432Node\\CLSID\\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\\InProcServer32","DesiredAccess":"0x2000000"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18dea4","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Wow6432Node\\CLSID\\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\\InProcServer32","DesiredAccess":"0x2000000"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18df20","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Wow6432Node\\CLSID\\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\\InProcServer32","DesiredAccess":"0x2000000"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18decc","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Wow6432Node\\CLSID\\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\\InProcServer32","DesiredAccess":"0x2000000"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e0a8","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Wow6432Node\\CLSID\\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\\InprocHandler32","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e0a8","objectName":"InprocHandler32","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e0a8","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Wow6432Node\\CLSID\\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\\InprocHandler","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e0a8","objectName":"InprocHandler","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e3d4","objectName":"Software\\Microsoft\\OLE","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKey #native (#2236) important_document.exe
- Arguments:
- {"DesiredAccess":"0x2000000","KeyHandle":"0x18d498","objectName":"\\Registry\\User\\S-1-5-21-364843204-231886559-199882026-1001_Classes"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18d734","objectName":"CLSID\\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18d734","objectName":"\\Registry\\Machine\\Software\\Classes\\CLSID\\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18d718","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Wow6432Node\\CLSID\\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\\TreatAs","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18d718","objectName":"TreatAs","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Windows\\system32\\propsys.dll"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18d324","objectName":"\\??\\C:\\Windows\\system32\\propsys.dll"}
- Returned value:
- null
- KernelBase.dll! LoadLibraryExA #misc (#2236) important_document.exe
- Arguments:
- {"lpFileName":"ADVAPI32.dll"}
- Returned value:
- 0x77300000
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"RegisterTraceGuidsW","hModule":"wmi.dll"}
- Returned value:
- 0x77a1f843
- KernelBase.dll! LoadLibraryExW #misc (#2236) important_document.exe
- Arguments:
- {"lpFileName":"propsys.dll"}
- Returned value:
- 0x726d0000
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"EventRegister","hModule":"api-ms-win-eventing-provider-l1-1-0.dll"}
- Returned value:
- 0x77a1f6ba
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"EventUnregister","hModule":"api-ms-win-eventing-provider-l1-1-0.dll"}
- Returned value:
- 0x77a39241
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"EventEnabled","hModule":"api-ms-win-eventing-provider-l1-1-0.dll"}
- Returned value:
- 0x77a188e2
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"EventWrite","hModule":"api-ms-win-eventing-provider-l1-1-0.dll"}
- Returned value:
- 0x77a40c59
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18d668","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Microsoft\\Windows\\Caches"}
- Returned value:
- null
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18da8c","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Microsoft\\Windows\\Caches\\cversions.1.db"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x3","dwFlagsAndAttributes":"0x0","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Microsoft\\Windows\\Caches\\cversions.1.db","dwDesiredAccess":"0x80000000","dwShareMode":"0x3"}
- Returned value:
- 0x1c0
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"InitializeSecurityDescriptor","hModule":"KernelBase.dll"}
- Returned value:
- 0x77314620
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"SetEntriesInAclW","hModule":"advapi32.dll"}
- Returned value:
- 0x77312a66
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18d620","objectName":"System\\CurrentControlSet\\Control\\LSA\\AccessProviders","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\Downloads\\ntmarta.dll"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Windows\\system32\\ntmarta.dll"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18d3dc","objectName":"\\??\\C:\\Windows\\system32\\ntmarta.dll"}
- Returned value:
- null
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18d23c","objectName":"System\\CurrentControlSet\\Services\\LDAP","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18d240","objectName":"System\\CurrentControlSet\\Services\\LDAP","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18d240","objectName":"System\\CurrentControlSet\\Services\\LDAP","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"GetMartaExtensionInterface","hModule":"ntmarta.dll"}
- Returned value:
- 0x741c21f2
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"SetSecurityDescriptorDacl","hModule":"KernelBase.dll"}
- Returned value:
- 0x7731415e
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18e0c8","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Microsoft\\Windows\\Caches\\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x000000000000000a.db"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x3","dwFlagsAndAttributes":"0x0","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Microsoft\\Windows\\Caches\\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x000000000000000a.db","dwDesiredAccess":"0x80000000","dwShareMode":"0x1"}
- Returned value:
- 0x1c0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18e51c","objectName":"\\??\\C:\\Users\\desktop.ini"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x3","dwFlagsAndAttributes":"0x8000000","lpFileName":"C:\\Users\\desktop.ini","dwDesiredAccess":"0x80000000","dwShareMode":"0x7"}
- Returned value:
- 0x1c4
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e474","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer","DesiredAccess":"0x1"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e474","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- KernelBase.dll! LoadLibraryExA #misc (#2236) important_document.exe
- Arguments:
- {"lpFileName":"ADVAPI32.dll"}
- Returned value:
- 0x77300000
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"OpenThreadToken","hModule":"KernelBase.dll"}
- Returned value:
- 0x7731432c
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e644","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer","DesiredAccess":"0x1"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e644","objectName":"","DesiredAccess":"0x1"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e3f0","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer","DesiredAccess":"0x1"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e3f0","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e3f0","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer","DesiredAccess":"0x1"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e3f0","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e3f0","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer","DesiredAccess":"0x1"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e3f0","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e3f0","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer","DesiredAccess":"0x1"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e3f0","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e3f0","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer","DesiredAccess":"0x1"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e3f0","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e5e4","objectName":"Advanced","DesiredAccess":"0x1"}
- Returned value:
- 0x0
- KernelBase.dll! LoadLibraryExA #misc (#2236) important_document.exe
- Arguments:
- {"lpFileName":"SHELL32.dll"}
- Returned value:
- 0x75d90000
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"0x66","hModule":null}
- Returned value:
- 0x75e2b7d9
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e137c","objectName":"Software\\Microsoft\\Windows\\Shell\\RegisteredApplications\\UrlAssociations\\Directory\\OpenWithProgids","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e137c","objectName":"Software\\Microsoft\\Windows\\Shell\\Associations\\UrlAssociations\\Directory","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e508","objectName":"Directory","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e508","objectName":"\\Registry\\Machine\\Software\\Classes\\Directory","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e480","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Directory\\CurVer","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e480","objectName":"CurVer","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e500","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Directory","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e500","objectName":"","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e137c","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Directory","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e137c","objectName":"","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e4cc","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Directory\\ShellEx\\IconHandler","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e4cc","objectName":"ShellEx\\IconHandler","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e1394","objectName":"Folder","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e1394","objectName":"\\Registry\\Machine\\Software\\Classes\\Folder","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e4cc","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Folder\\ShellEx\\IconHandler","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e4cc","objectName":"ShellEx\\IconHandler","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e13ac","objectName":"AllFilesystemObjects","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e13ac","objectName":"\\Registry\\Machine\\Software\\Classes\\AllFilesystemObjects","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e4cc","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\AllFilesystemObjects\\ShellEx\\IconHandler","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e4cc","objectName":"ShellEx\\IconHandler","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e474","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Directory","DesiredAccess":"0x2000000"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e60c","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Directory\\DocObject","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e60c","objectName":"DocObject","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e474","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Folder","DesiredAccess":"0x2000000"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e60c","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Folder\\DocObject","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e60c","objectName":"DocObject","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e474","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\AllFilesystemObjects","DesiredAccess":"0x2000000"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e60c","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\AllFilesystemObjects\\DocObject","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e60c","objectName":"DocObject","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e474","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Directory","DesiredAccess":"0x2000000"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e60c","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Directory\\BrowseInPlace","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e60c","objectName":"BrowseInPlace","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e474","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Folder","DesiredAccess":"0x2000000"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e60c","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Folder\\BrowseInPlace","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e60c","objectName":"BrowseInPlace","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e474","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\AllFilesystemObjects","DesiredAccess":"0x2000000"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e60c","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\AllFilesystemObjects\\BrowseInPlace","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e60c","objectName":"BrowseInPlace","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e1d4","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Directory\\Clsid","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e1d4","objectName":"Clsid","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e1f8","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Folder\\Clsid","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e1f8","objectName":"Clsid","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e1f8","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\AllFilesystemObjects\\Clsid","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e1f8","objectName":"Clsid","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e474","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Directory","DesiredAccess":"0x2000000"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e474","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Folder","DesiredAccess":"0x2000000"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e474","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\AllFilesystemObjects","DesiredAccess":"0x2000000"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e474","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Directory","DesiredAccess":"0x2000000"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e474","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Directory","DesiredAccess":"0x2000000"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e474","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Folder","DesiredAccess":"0x2000000"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e474","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\AllFilesystemObjects","DesiredAccess":"0x2000000"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18db20","objectName":"\\??\\C:\\Users"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x3","dwFlagsAndAttributes":"0x2000000","lpFileName":"C:\\Users","dwDesiredAccess":"0x100081","dwShareMode":"0x7"}
- Returned value:
- 0x1f0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18d5cc","objectName":"\\??\\C:\\Users\\admin"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x3","dwFlagsAndAttributes":"0x2000000","lpFileName":"C:\\Users\\admin","dwDesiredAccess":"0x100081","dwShareMode":"0x7"}
- Returned value:
- 0x1f0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18da74","objectName":"\\??\\C:\\Users\\<USER>\\Downloads\\desktop.ini"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x3","dwFlagsAndAttributes":"0x8000000","lpFileName":"C:\\Users\\<USER>\\Downloads\\desktop.ini","dwDesiredAccess":"0x80000000","dwShareMode":"0x7"}
- Returned value:
- 0x1f0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ef30","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18f06c","objectName":"{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7ca6c4","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ee30","objectName":"SessionInfo\\1","DesiredAccess":"0x1"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18eea8","objectName":"KnownFolders","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKey #native (#2236) important_document.exe
- Arguments:
- {"DesiredAccess":"0x20019","KeyHandle":"0x18f178","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18f1c0","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18d7c4","objectName":"\\??\\C:\\Users\\<USER>\\Desktop\\desktop.ini"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x3","dwFlagsAndAttributes":"0x8000000","lpFileName":"C:\\Users\\<USER>\\Desktop\\desktop.ini","dwDesiredAccess":"0x80000000","dwShareMode":"0x7"}
- Returned value:
- 0x1f8
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18f35c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\KnownFolderSettings","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18f35c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\KnownFolderSettings","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ef30","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18f06c","objectName":"{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6934","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ee30","objectName":"SessionInfo\\1","DesiredAccess":"0x1"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18eea8","objectName":"KnownFolders","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKey #native (#2236) important_document.exe
- Arguments:
- {"DesiredAccess":"0x20019","KeyHandle":"0x18f178","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18f1c0","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ed1c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ee58","objectName":"{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6954","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ee30","objectName":"SessionInfo\\1","DesiredAccess":"0x1"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18eea8","objectName":"KnownFolders","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ef30","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18f06c","objectName":"{5E6C858F-0E22-4760-9AFE-EA3317B67173}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6974","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18cf0c","objectName":"Software\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-21-364843204-231886559-199882026-1001","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ef30","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18f06c","objectName":"{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6994","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18f128","objectName":"CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18f128","objectName":"\\Registry\\Machine\\Software\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder","DesiredAccess":"0x1"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ef38","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Wow6432Node\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder","DesiredAccess":"0x2000000"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ef38","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Wow6432Node\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder","DesiredAccess":"0x2000000"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ef38","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Wow6432Node\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder","DesiredAccess":"0x2000000"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ef38","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Wow6432Node\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder","DesiredAccess":"0x2000000"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ef38","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Wow6432Node\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder","DesiredAccess":"0x2000000"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ef38","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Wow6432Node\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder","DesiredAccess":"0x2000000"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ef38","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Wow6432Node\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder","DesiredAccess":"0x2000000"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ef38","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Wow6432Node\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder","DesiredAccess":"0x2000000"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ef38","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Wow6432Node\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder","DesiredAccess":"0x2000000"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ef38","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Wow6432Node\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder","DesiredAccess":"0x2000000"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ef38","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Wow6432Node\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder","DesiredAccess":"0x2000000"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ef38","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Wow6432Node\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder","DesiredAccess":"0x2000000"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ef38","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Wow6432Node\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder","DesiredAccess":"0x2000000"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ef38","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Wow6432Node\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder","DesiredAccess":"0x2000000"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ef38","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Wow6432Node\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder","DesiredAccess":"0x2000000"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ef38","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Wow6432Node\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder","DesiredAccess":"0x2000000"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ef38","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Wow6432Node\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder","DesiredAccess":"0x2000000"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ef38","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001_Classes\\Wow6432Node\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder","DesiredAccess":"0x2000000"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18f0c8","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18f0c8","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18f05c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\NonEnum","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18f05c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\NonEnum","DesiredAccess":"0x1"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ee34","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6ab4","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e96c","objectName":"SessionInfo\\1","DesiredAccess":"0x1"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e9e4","objectName":"KnownFolders","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKey #native (#2236) important_document.exe
- Arguments:
- {"DesiredAccess":"0x20019","KeyHandle":"0x18ecb4","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ecfc","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ca48","objectName":"Software\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-21-364843204-231886559-199882026-1001","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{F38BF404-1D43-42F2-9305-67DE0B28FC23}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6ad4","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6ab4","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{2112AB0A-C86A-4FFE-A368-0DE96E47012E}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6ab4","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6b14","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6b14","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{9E52AB10-F80D-49DF-ACB8-4330F5687855}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6b34","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{98EC0E18-2098-4D44-8644-66979315A281}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6b54","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{A4115719-D62E-491D-AA7C-E74B8BE3B067}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6b54","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6b54","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{18989B1D-99B5-455B-841C-AB7C74E4DDFC}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6b74","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e96c","objectName":"SessionInfo\\1","DesiredAccess":"0x1"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e9e4","objectName":"KnownFolders","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKey #native (#2236) important_document.exe
- Arguments:
- {"DesiredAccess":"0x20019","KeyHandle":"0x18ecb4","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ecfc","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6b94","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{DE974D24-D9C6-4D3E-BF91-F4455120B917}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6b94","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6b94","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{76FC4E2D-D6AD-4519-A663-37BD56068185}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6b94","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6b94","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{491E922F-5643-4AF4-A7EB-4E7A138D8174}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6b94","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{33E28130-4E1E-4676-835A-98395C3BC3BB}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6bf4","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e96c","objectName":"SessionInfo\\1","DesiredAccess":"0x1"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e9e4","objectName":"KnownFolders","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKey #native (#2236) important_document.exe
- Arguments:
- {"DesiredAccess":"0x20019","KeyHandle":"0x18ecb4","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ecfc","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{8AD10C31-2ADB-4296-A8F7-E4701232C972}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6c14","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6c14","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{DEBF2536-E1A8-4C59-B6A2-414586476AEA}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6c14","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6c14","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{2400183A-6185-49FB-A2D8-4A392A602BA3}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6c54","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{D9DC8A3B-B784-432E-A781-5A1130A75963}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6c74","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{C4900540-2379-4C75-844B-64E6FAF8716B}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6c74","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{289A9A43-BE44-4057-A41B-587A76D7E7F9}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6c74","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{4BFEFB45-347D-4006-A5BE-AC0CB0567192}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6c74","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6c74","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6c94","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{C870044B-F49E-4126-A9C3-B52A1FF411E8}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6cb4","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6cd4","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{C5ABBF53-E17F-4121-8900-86626FC2C973}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6cd4","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{56784854-C6CB-462B-8169-88E350ACB882}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6d14","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e96c","objectName":"SessionInfo\\1","DesiredAccess":"0x1"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e9e4","objectName":"KnownFolders","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKey #native (#2236) important_document.exe
- Arguments:
- {"DesiredAccess":"0x20019","KeyHandle":"0x18ecb4","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ecfc","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ca48","objectName":"Software\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-21-364843204-231886559-199882026-1001","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6d54","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6d54","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{A302545D-DEFF-464B-ABE8-61C8648D939B}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6d54","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{2B0F765D-C0E9-4171-908E-08A611B84FF6}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6d34","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6d34","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{E555AB60-153B-4D17-9F04-A5FE99FC15EC}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6d34","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{054FAE61-4DD8-4787-80B6-090220C4B700}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6d74","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{1777F761-68AD-4D8A-87BD-30B759FA33DD}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6db4","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e96c","objectName":"SessionInfo\\1","DesiredAccess":"0x1"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e9e4","objectName":"KnownFolders","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKey #native (#2236) important_document.exe
- Arguments:
- {"DesiredAccess":"0x20019","KeyHandle":"0x18ecb4","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ecfc","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6db4","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6db4","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{8983036C-27C0-404B-8F08-102D10DCFD74}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6df4","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{BCB5256F-79F6-4CEE-B725-DC34E402FD46}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6df4","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{724EF170-A42D-4FEF-9F26-B60E846FBA4F}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6df4","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{4BD8D571-6D19-48D3-BE97-422220080E43}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6e14","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e96c","objectName":"SessionInfo\\1","DesiredAccess":"0x1"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e9e4","objectName":"KnownFolders","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKey #native (#2236) important_document.exe
- Arguments:
- {"DesiredAccess":"0x20019","KeyHandle":"0x18ecb4","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ecfc","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6e34","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{0762D272-C50A-4BB0-A382-697DCD729B80}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6e34","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6e34","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6e34","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6e94","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{0AC0837C-BBF8-452A-850D-79D08E667CA7}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6eb4","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{D0384E7D-BAC3-4797-8F14-CBA229B392B5}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6eb4","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6eb4","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{AE50C081-EBD2-438A-8655-8A092E34987A}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6e94","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6e94","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6e94","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6ed4","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6f14","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6f54","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{374DE290-123F-4565-9164-39C4925E467B}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6f94","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e96c","objectName":"SessionInfo\\1","DesiredAccess":"0x1"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e9e4","objectName":"KnownFolders","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKey #native (#2236) important_document.exe
- Arguments:
- {"DesiredAccess":"0x20019","KeyHandle":"0x18ecb4","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ecfc","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{859EAD94-2E85-48AD-A71A-0969CB56A6CD}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6fb4","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{A305CE99-F527-492B-8B1A-7E76FA98D6E4}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6fb4","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{3D644C9B-1FB8-4F30-9B45-F670235F79C0}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6f94","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{A990AE9F-A03B-4E80-94BC-9912D7504104}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6f94","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{DFDF76A2-C82A-4D63-906A-5644AC457385}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6fd4","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{1A6FDBA2-F42D-4358-A798-B74D745926C5}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6fd4","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{A520A1A4-1780-4FF6-BD18-167343C5AF16}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6fd4","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6ff4","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e6ff4","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{9E3995AB-1F9C-4F13-B827-48B24B6C7174}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e7034","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{DF7266AC-9274-4867-8D55-3BD661DE872D}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e7054","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{ED4824AF-DCE4-45A8-81E2-FC7965083634}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e7034","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7e7094","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7f52c4","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{3214FAB5-9757-4298-BB61-92A9DEAA44FF}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7f52e4","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{905E63B6-C1BF-494E-B29C-65B732D3D21A}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7f5304","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7f5324","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{B97D20BB-F46A-4C97-BA10-5E3608430854}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7f5344","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7f5364","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7f5364","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{DE92C1C7-837F-4F69-A3BB-86E631204A23}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7f53a4","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{10C07CD0-EF91-4567-B850-448B77CB37F9}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7f53a4","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{FDD39AD0-238F-46AF-ADB4-6C85480369C7}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7f5404","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e96c","objectName":"SessionInfo\\1","DesiredAccess":"0x1"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e9e4","objectName":"KnownFolders","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKey #native (#2236) important_document.exe
- Arguments:
- {"DesiredAccess":"0x20019","KeyHandle":"0x18ecb4","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ecfc","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7f5464","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{190337D1-B8CA-4121-A639-6D472D16972A}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7f5484","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7f5484","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7f5484","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e96c","objectName":"SessionInfo\\1","DesiredAccess":"0x1"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e9e4","objectName":"KnownFolders","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKey #native (#2236) important_document.exe
- Arguments:
- {"DesiredAccess":"0x20019","KeyHandle":"0x18ecb4","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ecfc","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ca48","objectName":"Software\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-21-364843204-231886559-199882026-1001","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7f5464","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{B94237E7-57AC-4347-9151-B08C6C32D1F7}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7f5464","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{352481E8-33BE-4251-BA85-6007CAEDCF9D}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7f5464","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{A63293E8-664E-48DB-A079-DF759E0509F7}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7f54a4","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{5CE4A5E9-E4EB-479D-B89F-130C02886155}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7f54a4","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{82A74AEB-AEB4-465C-A014-D097EE346D63}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7f54a4","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7f54a4","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{43668BF8-C14E-49B2-97C9-747784D784B7}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7f54c4","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7f54c4","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ea8c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ebc8","objectName":"{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x7f5504","objectName":"PropertyBag","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e96c","objectName":"SessionInfo\\1","DesiredAccess":"0x1"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e9e4","objectName":"KnownFolders","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKey #native (#2236) important_document.exe
- Arguments:
- {"DesiredAccess":"0x20019","KeyHandle":"0x18ecb4","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ecfc","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ca48","objectName":"Software\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-21-364843204-231886559-199882026-1001","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e710","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e92c","objectName":"{e9b1a4f8-a98b-11e9-a299-806e6f6e6963}\\","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18d694","objectName":"\\??\\C:\\"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x3","dwFlagsAndAttributes":"0x2000000","lpFileName":"C:\\","dwDesiredAccess":"0x100081","dwShareMode":"0x7"}
- Returned value:
- 0x250
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18d140","objectName":"\\??\\C:\\Users"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x3","dwFlagsAndAttributes":"0x2000000","lpFileName":"C:\\Users","dwDesiredAccess":"0x100081","dwShareMode":"0x7"}
- Returned value:
- 0x250
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18cbec","objectName":"\\??\\C:\\Users\\admin"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x3","dwFlagsAndAttributes":"0x2000000","lpFileName":"C:\\Users\\admin","dwDesiredAccess":"0x100081","dwShareMode":"0x7"}
- Returned value:
- 0x250
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18d094","objectName":"\\??\\C:\\Users\\<USER>\\Searches\\desktop.ini"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x3","dwFlagsAndAttributes":"0x8000000","lpFileName":"C:\\Users\\<USER>\\Searches\\desktop.ini","dwDesiredAccess":"0x80000000","dwShareMode":"0x7"}
- Returned value:
- 0x250
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"CoTaskMemFree","hModule":"ole32.dll"}
- Returned value:
- 0x75776f41
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e710","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e92c","objectName":"{e9b1a4f8-a98b-11e9-a299-806e6f6e6963}\\","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18d694","objectName":"\\??\\C:\\"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x3","dwFlagsAndAttributes":"0x2000000","lpFileName":"C:\\","dwDesiredAccess":"0x100081","dwShareMode":"0x7"}
- Returned value:
- 0x24c
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18d140","objectName":"\\??\\C:\\Users"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x3","dwFlagsAndAttributes":"0x2000000","lpFileName":"C:\\Users","dwDesiredAccess":"0x100081","dwShareMode":"0x7"}
- Returned value:
- 0x24c
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18cbec","objectName":"\\??\\C:\\Users\\admin"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x3","dwFlagsAndAttributes":"0x2000000","lpFileName":"C:\\Users\\admin","dwDesiredAccess":"0x100081","dwShareMode":"0x7"}
- Returned value:
- 0x24c
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18d094","objectName":"\\??\\C:\\Users\\<USER>\\Videos\\desktop.ini"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x3","dwFlagsAndAttributes":"0x8000000","lpFileName":"C:\\Users\\<USER>\\Videos\\desktop.ini","dwDesiredAccess":"0x80000000","dwShareMode":"0x7"}
- Returned value:
- 0x24c
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e710","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e92c","objectName":"{e9b1a4f8-a98b-11e9-a299-806e6f6e6963}\\","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18d694","objectName":"\\??\\C:\\"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x3","dwFlagsAndAttributes":"0x2000000","lpFileName":"C:\\","dwDesiredAccess":"0x100081","dwShareMode":"0x7"}
- Returned value:
- 0x250
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18d140","objectName":"\\??\\C:\\Users"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x3","dwFlagsAndAttributes":"0x2000000","lpFileName":"C:\\Users","dwDesiredAccess":"0x100081","dwShareMode":"0x7"}
- Returned value:
- 0x250
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18cbec","objectName":"\\??\\C:\\Users\\admin"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x3","dwFlagsAndAttributes":"0x2000000","lpFileName":"C:\\Users\\admin","dwDesiredAccess":"0x100081","dwShareMode":"0x7"}
- Returned value:
- 0x250
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18d094","objectName":"\\??\\C:\\Users\\<USER>\\Pictures\\desktop.ini"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x3","dwFlagsAndAttributes":"0x8000000","lpFileName":"C:\\Users\\<USER>\\Pictures\\desktop.ini","dwDesiredAccess":"0x80000000","dwShareMode":"0x7"}
- Returned value:
- 0x250
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e710","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e92c","objectName":"{e9b1a4f8-a98b-11e9-a299-806e6f6e6963}\\","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18d694","objectName":"\\??\\C:\\"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x3","dwFlagsAndAttributes":"0x2000000","lpFileName":"C:\\","dwDesiredAccess":"0x100081","dwShareMode":"0x7"}
- Returned value:
- 0x24c
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18d140","objectName":"\\??\\C:\\Users"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x3","dwFlagsAndAttributes":"0x2000000","lpFileName":"C:\\Users","dwDesiredAccess":"0x100081","dwShareMode":"0x7"}
- Returned value:
- 0x24c
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18cbec","objectName":"\\??\\C:\\Users\\admin"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x3","dwFlagsAndAttributes":"0x2000000","lpFileName":"C:\\Users\\admin","dwDesiredAccess":"0x100081","dwShareMode":"0x7"}
- Returned value:
- 0x24c
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e710","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e92c","objectName":"{e9b1a4f8-a98b-11e9-a299-806e6f6e6963}\\","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18d694","objectName":"\\??\\C:\\"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x3","dwFlagsAndAttributes":"0x2000000","lpFileName":"C:\\","dwDesiredAccess":"0x100081","dwShareMode":"0x7"}
- Returned value:
- 0x250
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18d140","objectName":"\\??\\C:\\Users"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x3","dwFlagsAndAttributes":"0x2000000","lpFileName":"C:\\Users","dwDesiredAccess":"0x100081","dwShareMode":"0x7"}
- Returned value:
- 0x250
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18cbec","objectName":"\\??\\C:\\Users\\admin"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x3","dwFlagsAndAttributes":"0x2000000","lpFileName":"C:\\Users\\admin","dwDesiredAccess":"0x100081","dwShareMode":"0x7"}
- Returned value:
- 0x250
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18d094","objectName":"\\??\\C:\\Users\\<USER>\\Contacts\\desktop.ini"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x3","dwFlagsAndAttributes":"0x8000000","lpFileName":"C:\\Users\\<USER>\\Contacts\\desktop.ini","dwDesiredAccess":"0x80000000","dwShareMode":"0x7"}
- Returned value:
- 0x250
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e710","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e92c","objectName":"{e9b1a4f8-a98b-11e9-a299-806e6f6e6963}\\","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18d694","objectName":"\\??\\C:\\"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x3","dwFlagsAndAttributes":"0x2000000","lpFileName":"C:\\","dwDesiredAccess":"0x100081","dwShareMode":"0x7"}
- Returned value:
- 0x24c
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18d140","objectName":"\\??\\C:\\Users"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x3","dwFlagsAndAttributes":"0x2000000","lpFileName":"C:\\Users","dwDesiredAccess":"0x100081","dwShareMode":"0x7"}
- Returned value:
- 0x24c
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18cbec","objectName":"\\??\\C:\\Users\\admin"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x3","dwFlagsAndAttributes":"0x2000000","lpFileName":"C:\\Users\\admin","dwDesiredAccess":"0x100081","dwShareMode":"0x7"}
- Returned value:
- 0x24c
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18d094","objectName":"\\??\\C:\\Users\\<USER>\\Favorites\\desktop.ini"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x3","dwFlagsAndAttributes":"0x8000000","lpFileName":"C:\\Users\\<USER>\\Favorites\\desktop.ini","dwDesiredAccess":"0x80000000","dwShareMode":"0x7"}
- Returned value:
- 0x24c
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e710","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e92c","objectName":"{e9b1a4f8-a98b-11e9-a299-806e6f6e6963}\\","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18d694","objectName":"\\??\\C:\\"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x3","dwFlagsAndAttributes":"0x2000000","lpFileName":"C:\\","dwDesiredAccess":"0x100081","dwShareMode":"0x7"}
- Returned value:
- 0x250
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18d140","objectName":"\\??\\C:\\Users"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x3","dwFlagsAndAttributes":"0x2000000","lpFileName":"C:\\Users","dwDesiredAccess":"0x100081","dwShareMode":"0x7"}
- Returned value:
- 0x250
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18cbec","objectName":"\\??\\C:\\Users\\admin"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x3","dwFlagsAndAttributes":"0x2000000","lpFileName":"C:\\Users\\admin","dwDesiredAccess":"0x100081","dwShareMode":"0x7"}
- Returned value:
- 0x250
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18d094","objectName":"\\??\\C:\\Users\\<USER>\\Music\\desktop.ini"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x3","dwFlagsAndAttributes":"0x8000000","lpFileName":"C:\\Users\\<USER>\\Music\\desktop.ini","dwDesiredAccess":"0x80000000","dwShareMode":"0x7"}
- Returned value:
- 0x250
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e710","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e92c","objectName":"{e9b1a4f8-a98b-11e9-a299-806e6f6e6963}\\","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18d694","objectName":"\\??\\C:\\"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x3","dwFlagsAndAttributes":"0x2000000","lpFileName":"C:\\","dwDesiredAccess":"0x100081","dwShareMode":"0x7"}
- Returned value:
- 0x24c
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18d140","objectName":"\\??\\C:\\Users"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x3","dwFlagsAndAttributes":"0x2000000","lpFileName":"C:\\Users","dwDesiredAccess":"0x100081","dwShareMode":"0x7"}
- Returned value:
- 0x24c
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18cbec","objectName":"\\??\\C:\\Users\\admin"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x3","dwFlagsAndAttributes":"0x2000000","lpFileName":"C:\\Users\\admin","dwDesiredAccess":"0x100081","dwShareMode":"0x7"}
- Returned value:
- 0x24c
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e710","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e92c","objectName":"{e9b1a4f8-a98b-11e9-a299-806e6f6e6963}\\","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18d694","objectName":"\\??\\C:\\"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x3","dwFlagsAndAttributes":"0x2000000","lpFileName":"C:\\","dwDesiredAccess":"0x100081","dwShareMode":"0x7"}
- Returned value:
- 0x250
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18d140","objectName":"\\??\\C:\\Users"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x3","dwFlagsAndAttributes":"0x2000000","lpFileName":"C:\\Users","dwDesiredAccess":"0x100081","dwShareMode":"0x7"}
- Returned value:
- 0x250
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18cbec","objectName":"\\??\\C:\\Users\\admin"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x3","dwFlagsAndAttributes":"0x2000000","lpFileName":"C:\\Users\\admin","dwDesiredAccess":"0x100081","dwShareMode":"0x7"}
- Returned value:
- 0x250
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18d094","objectName":"\\??\\C:\\Users\\<USER>\\Documents\\desktop.ini"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x3","dwFlagsAndAttributes":"0x8000000","lpFileName":"C:\\Users\\<USER>\\Documents\\desktop.ini","dwDesiredAccess":"0x80000000","dwShareMode":"0x7"}
- Returned value:
- 0x250
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e710","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e92c","objectName":"{e9b1a4f8-a98b-11e9-a299-806e6f6e6963}\\","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18d694","objectName":"\\??\\C:\\"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x3","dwFlagsAndAttributes":"0x2000000","lpFileName":"C:\\","dwDesiredAccess":"0x100081","dwShareMode":"0x7"}
- Returned value:
- 0x24c
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18d140","objectName":"\\??\\C:\\Users"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x3","dwFlagsAndAttributes":"0x2000000","lpFileName":"C:\\Users","dwDesiredAccess":"0x100081","dwShareMode":"0x7"}
- Returned value:
- 0x24c
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18cbec","objectName":"\\??\\C:\\Users\\admin"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x3","dwFlagsAndAttributes":"0x2000000","lpFileName":"C:\\Users\\admin","dwDesiredAccess":"0x100081","dwShareMode":"0x7"}
- Returned value:
- 0x24c
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18d094","objectName":"\\??\\C:\\Users\\<USER>\\Links\\desktop.ini"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x3","dwFlagsAndAttributes":"0x8000000","lpFileName":"C:\\Users\\<USER>\\Links\\desktop.ini","dwDesiredAccess":"0x80000000","dwShareMode":"0x7"}
- Returned value:
- 0x24c
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e710","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18e92c","objectName":"{e9b1a4f8-a98b-11e9-a299-806e6f6e6963}\\","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18d694","objectName":"\\??\\C:\\"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x3","dwFlagsAndAttributes":"0x2000000","lpFileName":"C:\\","dwDesiredAccess":"0x100081","dwShareMode":"0x7"}
- Returned value:
- 0x250
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18d140","objectName":"\\??\\C:\\Users"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x3","dwFlagsAndAttributes":"0x2000000","lpFileName":"C:\\Users","dwDesiredAccess":"0x100081","dwShareMode":"0x7"}
- Returned value:
- 0x250
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18cbec","objectName":"\\??\\C:\\Users\\admin"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x3","dwFlagsAndAttributes":"0x2000000","lpFileName":"C:\\Users\\admin","dwDesiredAccess":"0x100081","dwShareMode":"0x7"}
- Returned value:
- 0x250
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18d094","objectName":"\\??\\C:\\Users\\<USER>\\Saved Games\\desktop.ini"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x3","dwFlagsAndAttributes":"0x8000000","lpFileName":"C:\\Users\\<USER>\\Saved Games\\desktop.ini","dwDesiredAccess":"0x80000000","dwShareMode":"0x7"}
- Returned value:
- 0x250
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18fdbc","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\"}
- Returned value:
- null
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18fd20","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsiFE32.tmp"}
- Returned value:
- null
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18fdd0","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsiFE32.tmp"}
- Returned value:
- null
- KernelBase.dll! DeleteFileA #file (#2236) important_document.exe
- Arguments:
- {"lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsiFE32.tmp"}
- Returned value:
- 0x1
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\Downloads\\important_document.exe"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18fd24","objectName":"\\??\\C:\\Users\\<USER>\\Downloads\\important_document.exe"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x3","dwFlagsAndAttributes":"0x20","lpFileName":"C:\\Users\\<USER>\\Downloads\\important_document.exe","dwDesiredAccess":"0x80000000","dwShareMode":"0x1"}
- Returned value:
- 0x250
- KernelBase.dll! CreateFileA #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x3","dwFlagsAndAttributes":"0x20","lpFileName":"C:\\Users\\<USER>\\Downloads\\important_document.exe","dwDesiredAccess":"0x80000000","dwShareMode":"0x1"}
- Returned value:
- 0x250
- KernelBase.dll! GetFileSize #file (#2236) important_document.exe
- Arguments:
- {"lpFileSizeHigh":"0x5d3b680","hFile":"0x250"}
- Returned value:
- null
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"GetUserDefaultUILanguage","hModule":"KernelBase.dll"}
- Returned value:
- 0x773e44ab
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18fdd0","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\App Paths\\lightfactory.exe","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- kernel32.dll! RegOpenKeyExA #registry (#2236) important_document.exe
- Arguments:
- {"hKey":"HKEY_LOCAL_MACHINE","ulOptions":"0x0","samDesired":"0x20019","lpSubKey":"Software\\Microsoft\\Windows\\CurrentVersion\\App Paths\\lightfactory.exe","phkResult":"0x0"}
- Returned value:
- 0x2
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18fd9c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- kernel32.dll! RegOpenKeyExA #registry (#2236) important_document.exe
- Arguments:
- {"hKey":"HKEY_LOCAL_MACHINE","ulOptions":"0x0","samDesired":"0x20019","lpSubKey":"Software\\Microsoft\\Windows\\CurrentVersion","phkResult":"0x260"}
- Returned value:
- 0x0
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Windows\\system32\\RichEd20.dll"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18fa44","objectName":"\\??\\C:\\Windows\\system32\\RichEd20.dll"}
- Returned value:
- null
- ntdll.dll! NtOpenKey #native (#2236) important_document.exe
- Arguments:
- {"DesiredAccess":"0x20019","KeyHandle":"0x18f374","objectName":"\\Registry\\Machine\\System\\CurrentControlSet\\Control\\Nls\\Locale"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKey #native (#2236) important_document.exe
- Arguments:
- {"DesiredAccess":"0x20019","KeyHandle":"0x18f374","objectName":"\\Registry\\Machine\\System\\CurrentControlSet\\Control\\Nls\\Locale\\Alternate Sorts"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKey #native (#2236) important_document.exe
- Arguments:
- {"DesiredAccess":"0x20019","KeyHandle":"0x18f374","objectName":"\\Registry\\Machine\\System\\CurrentControlSet\\Control\\Nls\\Language Groups"}
- Returned value:
- 0x0
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"RegisterClassNameW","hModule":"comctl32.dll"}
- Returned value:
- 0x74291339
- KernelBase.dll! LoadLibraryExA #misc (#2236) important_document.exe
- Arguments:
- {"lpFileName":"UxTheme.dll"}
- Returned value:
- 0x727d0000
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"EnableThemeDialogTexture","hModule":"uxtheme.dll"}
- Returned value:
- 0x727f786d
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"RegisterClassNameW","hModule":"comctl32.dll"}
- Returned value:
- 0x74291339
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"OpenThemeData","hModule":"uxtheme.dll"}
- Returned value:
- 0x727e5f29
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f6ac","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp"}
- Returned value:
- null
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f0dc","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\"}
- Returned value:
- null
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f5f4","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp"}
- Returned value:
- null
- KernelBase.dll! DeleteFileA #file (#2236) important_document.exe
- Arguments:
- {"lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp"}
- Returned value:
- 0x1
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f750","objectName":"\\??\\C:\\Users"}
- Returned value:
- null
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f750","objectName":"\\??\\C:\\Users\\admin"}
- Returned value:
- null
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\admin"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f750","objectName":"\\??\\C:\\Users\\<USER>\\AppData"}
- Returned value:
- null
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f750","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local"}
- Returned value:
- null
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f750","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp"}
- Returned value:
- null
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f750","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp"}
- Returned value:
- null
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f914","objectName":"\\??\\C:\\Users"}
- Returned value:
- null
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f914","objectName":"\\??\\C:\\Users\\admin"}
- Returned value:
- null
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\admin"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f914","objectName":"\\??\\C:\\Users\\<USER>\\AppData"}
- Returned value:
- null
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f914","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local"}
- Returned value:
- null
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f914","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp"}
- Returned value:
- null
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f914","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp"}
- Returned value:
- null
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f8e8","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp"}
- Returned value:
- null
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\header.bmp"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\header.bmp"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f8ac","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\header.bmp"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x2","dwFlagsAndAttributes":"0x0","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\header.bmp","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0x1c
- KernelBase.dll! CreateFileA #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x2","dwFlagsAndAttributes":"0x0","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\header.bmp","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0x1c
- KernelBase.dll! WriteFile #file (#2236) important_document.exe
- Arguments:
- {"nNumberOfBytesToWrite":"0x11a","lpBuffer":"BM\u001a\u0001","lpNumberOfBytesWritten":"0x18f91c","hFile":"0x1c"}
- Returned value:
- 0x1
- KernelBase.dll! SetFileTime #highlighted (#2236) important_document.exe
- Arguments:
- {"desc":"Tries to modify filetime by calling kernel32.dll!SetFileTime"}
- Returned value:
- null
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\btmimg.bmp"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\btmimg.bmp"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f8ac","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\btmimg.bmp"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x2","dwFlagsAndAttributes":"0x0","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\btmimg.bmp","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0x1c
- KernelBase.dll! CreateFileA #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x2","dwFlagsAndAttributes":"0x0","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\btmimg.bmp","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0x1c
- KernelBase.dll! SetFileTime #highlighted (#2236) important_document.exe
- Arguments:
- {"desc":"Tries to modify filetime by calling kernel32.dll!SetFileTime"}
- Returned value:
- null
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\leftimg.bmp"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\leftimg.bmp"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f8ac","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\leftimg.bmp"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x2","dwFlagsAndAttributes":"0x0","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\leftimg.bmp","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0x1c
- KernelBase.dll! CreateFileA #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x2","dwFlagsAndAttributes":"0x0","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\leftimg.bmp","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0x1c
- KernelBase.dll! SetFileTime #highlighted (#2236) important_document.exe
- Arguments:
- {"desc":"Tries to modify filetime by calling kernel32.dll!SetFileTime"}
- Returned value:
- null
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\Header.bmp"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f324","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\Header.bmp"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x3","dwFlagsAndAttributes":"0x0","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\Header.bmp","dwDesiredAccess":"0x80000000","dwShareMode":"0x1"}
- Returned value:
- 0x1c
- KernelBase.dll! GetFileSize #file (#2236) important_document.exe
- Arguments:
- {"lpFileSizeHigh":"0x11a","hFile":"0x1c"}
- Returned value:
- null
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\Leftimg.bmp"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f324","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\Leftimg.bmp"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x3","dwFlagsAndAttributes":"0x0","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\Leftimg.bmp","dwDesiredAccess":"0x80000000","dwShareMode":"0x1"}
- Returned value:
- 0x1c
- KernelBase.dll! GetFileSize #file (#2236) important_document.exe
- Arguments:
- {"lpFileSizeHigh":"0x3d5c6","hFile":"0x1c"}
- Returned value:
- null
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\Btmimg.bmp"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f324","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\Btmimg.bmp"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x3","dwFlagsAndAttributes":"0x0","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\Btmimg.bmp","dwDesiredAccess":"0x80000000","dwShareMode":"0x1"}
- Returned value:
- 0x1c
- KernelBase.dll! GetFileSize #file (#2236) important_document.exe
- Arguments:
- {"lpFileSizeHigh":"0x238f6","hFile":"0x1c"}
- Returned value:
- null
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f914","objectName":"\\??\\C:\\Users"}
- Returned value:
- null
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f914","objectName":"\\??\\C:\\Users\\admin"}
- Returned value:
- null
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\admin"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f914","objectName":"\\??\\C:\\Users\\<USER>\\AppData"}
- Returned value:
- null
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f914","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local"}
- Returned value:
- null
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f914","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp"}
- Returned value:
- null
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f914","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp"}
- Returned value:
- null
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp"}
- Returned value:
- 0x0
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\isWelcome.ini"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\isWelcome.ini"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f8ac","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\isWelcome.ini"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x2","dwFlagsAndAttributes":"0x0","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\isWelcome.ini","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0x1c
- KernelBase.dll! CreateFileA #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x2","dwFlagsAndAttributes":"0x0","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\isWelcome.ini","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0x1c
- KernelBase.dll! SetFileTime #highlighted (#2236) important_document.exe
- Arguments:
- {"desc":"Tries to modify filetime by calling kernel32.dll!SetFileTime"}
- Returned value:
- null
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\Finish.ini"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\Finish.ini"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f8ac","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\Finish.ini"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x2","dwFlagsAndAttributes":"0x0","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\Finish.ini","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0x1c
- KernelBase.dll! CreateFileA #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x2","dwFlagsAndAttributes":"0x0","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\Finish.ini","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0x1c
- KernelBase.dll! SetFileTime #highlighted (#2236) important_document.exe
- Arguments:
- {"desc":"Tries to modify filetime by calling kernel32.dll!SetFileTime"}
- Returned value:
- null
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f914","objectName":"\\??\\C:\\Users"}
- Returned value:
- null
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f914","objectName":"\\??\\C:\\Users\\admin"}
- Returned value:
- null
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\admin"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f914","objectName":"\\??\\C:\\Users\\<USER>\\AppData"}
- Returned value:
- null
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f914","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local"}
- Returned value:
- null
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f914","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp"}
- Returned value:
- null
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f914","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp"}
- Returned value:
- null
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f410","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\"}
- Returned value:
- null
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\StartMenu.ini"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\StartMenu.ini"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f8ac","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\StartMenu.ini"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x2","dwFlagsAndAttributes":"0x0","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\StartMenu.ini","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0x1c
- KernelBase.dll! CreateFileA #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x2","dwFlagsAndAttributes":"0x0","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\StartMenu.ini","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0x1c
- KernelBase.dll! SetFileTime #highlighted (#2236) important_document.exe
- Arguments:
- {"desc":"Tries to modify filetime by calling kernel32.dll!SetFileTime"}
- Returned value:
- null
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f8ac","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x0","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0x1c
- KernelBase.dll! CreateFileA #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x0","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0x1c
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f29c","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- null
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f29c","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- null
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f6f8","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- null
- ntdll.dll! NtOpenKey #native (#2236) important_document.exe
- Arguments:
- {"DesiredAccess":"0x9","KeyHandle":"0x18f3ec","objectName":"DllNXOptions"}
- Returned value:
- 0x0
- KernelBase.dll! LoadLibraryExA #misc (#2236) important_document.exe
- Arguments:
- {"lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- 0x10000000
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"ErrorStyle","hModule":null}
- Returned value:
- 0x10001151
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f8ac","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! CreateFileA #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"ErrorStyle","hModule":null}
- Returned value:
- 0x10001151
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f8ac","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! CreateFileA #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"New","hModule":null}
- Returned value:
- 0x1000127d
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18f078","objectName":"SessionInfo\\1","DesiredAccess":"0x1"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18f0f0","objectName":"KnownFolders","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKey #native (#2236) important_document.exe
- Arguments:
- {"DesiredAccess":"0x20019","KeyHandle":"0x18f3c0","objectName":"\\REGISTRY\\USER\\S-1-5-21-364843204-231886559-199882026-1001"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18f408","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs"}
- Returned value:
- 0x0
- KernelBase.dll! GetFileAttributesW #file (#2236) important_document.exe
- Arguments:
- {"lpFileName":"C:\\Users\\<USER>\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs"}
- Returned value:
- 0x11
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f41c","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\"}
- Returned value:
- null
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f410","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\"}
- Returned value:
- null
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f8ac","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! CreateFileA #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"ExistsI","hModule":null}
- Returned value:
- 0x100030ec
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f8ac","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! CreateFileA #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"Push","hModule":null}
- Returned value:
- 0x10001ed7
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f410","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Administrative Tools\\"}
- Returned value:
- null
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f8ac","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! CreateFileA #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"ExistsI","hModule":null}
- Returned value:
- 0x100030ec
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f8ac","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! CreateFileA #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"Push","hModule":null}
- Returned value:
- 0x10001ed7
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f410","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\desktop.ini\\"}
- Returned value:
- null
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f410","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Internet Explorer (64-bit).lnk\\"}
- Returned value:
- null
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f410","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Internet Explorer.lnk\\"}
- Returned value:
- null
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f410","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Maintenance\\"}
- Returned value:
- null
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f8ac","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! CreateFileA #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"ExistsI","hModule":null}
- Returned value:
- 0x100030ec
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f8ac","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! CreateFileA #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"Push","hModule":null}
- Returned value:
- 0x10001ed7
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f410","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Python 3.7\\"}
- Returned value:
- null
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f8ac","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! CreateFileA #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"ExistsI","hModule":null}
- Returned value:
- 0x100030ec
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f8ac","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! CreateFileA #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"Push","hModule":null}
- Returned value:
- 0x10001ed7
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f410","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\"}
- Returned value:
- null
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f8ac","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! CreateFileA #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"ExistsI","hModule":null}
- Returned value:
- 0x100030ec
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f8ac","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! CreateFileA #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"Push","hModule":null}
- Returned value:
- 0x10001ed7
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18f078","objectName":"SessionInfo\\1","DesiredAccess":"0x1"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18f0f0","objectName":"KnownFolders","DesiredAccess":"0x1"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18f40c","objectName":"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs"}
- Returned value:
- 0x0
- KernelBase.dll! GetFileAttributesW #file (#2236) important_document.exe
- Arguments:
- {"lpFileName":"C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs"}
- Returned value:
- 0x11
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f41c","objectName":"\\??\\C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\"}
- Returned value:
- null
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f410","objectName":"\\??\\C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\"}
- Returned value:
- null
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f8ac","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! CreateFileA #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"ExistsI","hModule":null}
- Returned value:
- 0x100030ec
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f410","objectName":"\\??\\C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Acrobat Reader DC.lnk\\"}
- Returned value:
- null
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f410","objectName":"\\??\\C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Administrative Tools\\"}
- Returned value:
- null
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f8ac","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! CreateFileA #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"ExistsI","hModule":null}
- Returned value:
- 0x100030ec
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f410","objectName":"\\??\\C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\desktop.ini\\"}
- Returned value:
- null
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f410","objectName":"\\??\\C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Firefox.lnk\\"}
- Returned value:
- null
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f410","objectName":"\\??\\C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Games\\"}
- Returned value:
- null
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f8ac","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! CreateFileA #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"ExistsI","hModule":null}
- Returned value:
- 0x100030ec
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f8ac","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! CreateFileA #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"Push","hModule":null}
- Returned value:
- 0x10001ed7
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f410","objectName":"\\??\\C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Google Chrome.lnk\\"}
- Returned value:
- null
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f410","objectName":"\\??\\C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Java\\"}
- Returned value:
- null
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f8ac","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! CreateFileA #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"ExistsI","hModule":null}
- Returned value:
- 0x100030ec
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f8ac","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! CreateFileA #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"Push","hModule":null}
- Returned value:
- 0x10001ed7
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f410","objectName":"\\??\\C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Maintenance\\"}
- Returned value:
- null
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f8ac","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! CreateFileA #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"ExistsI","hModule":null}
- Returned value:
- 0x100030ec
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f410","objectName":"\\??\\C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Media Center.lnk\\"}
- Returned value:
- null
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f410","objectName":"\\??\\C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\OpenOffice 4.1.6\\"}
- Returned value:
- null
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f8ac","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! CreateFileA #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"ExistsI","hModule":null}
- Returned value:
- 0x100030ec
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f8ac","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! CreateFileA #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"Push","hModule":null}
- Returned value:
- 0x10001ed7
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f410","objectName":"\\??\\C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Sidebar.lnk\\"}
- Returned value:
- null
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f410","objectName":"\\??\\C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\"}
- Returned value:
- null
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f8ac","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! CreateFileA #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"ExistsI","hModule":null}
- Returned value:
- 0x100030ec
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f410","objectName":"\\??\\C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Steam\\"}
- Returned value:
- null
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f8ac","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! CreateFileA #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"ExistsI","hModule":null}
- Returned value:
- 0x100030ec
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f8ac","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! CreateFileA #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"Push","hModule":null}
- Returned value:
- 0x10001ed7
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f410","objectName":"\\??\\C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Sublime Text 3.lnk\\"}
- Returned value:
- null
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f410","objectName":"\\??\\C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Tablet PC\\"}
- Returned value:
- null
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f8ac","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! CreateFileA #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"ExistsI","hModule":null}
- Returned value:
- 0x100030ec
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f8ac","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! CreateFileA #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"Push","hModule":null}
- Returned value:
- 0x10001ed7
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f410","objectName":"\\??\\C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Windows DVD Maker.lnk\\"}
- Returned value:
- null
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f410","objectName":"\\??\\C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Windows Fax and Scan.lnk\\"}
- Returned value:
- null
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f410","objectName":"\\??\\C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Windows Media Player.lnk\\"}
- Returned value:
- null
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f410","objectName":"\\??\\C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\XPS Viewer.lnk\\"}
- Returned value:
- null
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f8ac","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! CreateFileA #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"Sort","hModule":null}
- Returned value:
- 0x10002aa0
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f8ac","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! CreateFileA #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"SizeOf","hModule":null}
- Returned value:
- 0x10003491
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f8ac","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! CreateFileA #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"Read","hModule":null}
- Returned value:
- 0x10001b73
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f8ac","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! CreateFileA #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"SizeOf","hModule":null}
- Returned value:
- 0x10003491
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f8ac","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! CreateFileA #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"Read","hModule":null}
- Returned value:
- 0x10001b73
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f8ac","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! CreateFileA #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"SizeOf","hModule":null}
- Returned value:
- 0x10003491
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f8ac","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! CreateFileA #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"Read","hModule":null}
- Returned value:
- 0x10001b73
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f8ac","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! CreateFileA #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"SizeOf","hModule":null}
- Returned value:
- 0x10003491
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f8ac","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! CreateFileA #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"Read","hModule":null}
- Returned value:
- 0x10001b73
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f8ac","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! CreateFileA #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"SizeOf","hModule":null}
- Returned value:
- 0x10003491
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f8ac","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! CreateFileA #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"Read","hModule":null}
- Returned value:
- 0x10001b73
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f8ac","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! CreateFileA #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"SizeOf","hModule":null}
- Returned value:
- 0x10003491
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f8ac","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! CreateFileA #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"Read","hModule":null}
- Returned value:
- 0x10001b73
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f8ac","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! CreateFileA #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"SizeOf","hModule":null}
- Returned value:
- 0x10003491
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f8ac","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! CreateFileA #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"Read","hModule":null}
- Returned value:
- 0x10001b73
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f8ac","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! CreateFileA #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"SizeOf","hModule":null}
- Returned value:
- 0x10003491
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f8ac","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! CreateFileA #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"Read","hModule":null}
- Returned value:
- 0x10001b73
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f8ac","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! CreateFileA #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"SizeOf","hModule":null}
- Returned value:
- 0x10003491
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f8ac","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! CreateFileA #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"Read","hModule":null}
- Returned value:
- 0x10001b73
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f8ac","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! CreateFileA #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"SizeOf","hModule":null}
- Returned value:
- 0x10003491
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f8ac","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! CreateFileA #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"Read","hModule":null}
- Returned value:
- 0x10001b73
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f8ac","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! CreateFileA #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"SizeOf","hModule":null}
- Returned value:
- 0x10003491
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f8ac","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! CreateFileA #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"Delete","hModule":null}
- Returned value:
- 0x100021e0
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f8ac","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! CreateFileA #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"ArrayCount","hModule":null}
- Returned value:
- 0x1000173d
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f8ac","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! CreateFileA #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\NSISArray.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"Unload","hModule":null}
- Returned value:
- 0x10003692
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x82c59c","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\StartMenu.ini"}
- Returned value:
- null
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18f090","objectName":"SOFTWARE\\Microsoft\\CTF\\Compatibility\\important_document.exe","DesiredAccess":"0x20019"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Windows\\system32\\ole32.dll"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f264","objectName":"\\??\\C:\\Windows\\system32\\ole32.dll"}
- Returned value:
- null
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"CoInitializeEx","hModule":"ole32.dll"}
- Returned value:
- 0x757609ad
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"CoUninitialize","hModule":"ole32.dll"}
- Returned value:
- 0x757686d3
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"CoRegisterInitializeSpy","hModule":"ole32.dll"}
- Returned value:
- 0x75767660
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"CoRevokeInitializeSpy","hModule":"ole32.dll"}
- Returned value:
- 0x75769784
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18f644","objectName":"Software\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\LanguageProfile\\0x00000000\\{0001bea3-ed56-483d-a2e2-aeae25577436}","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenMutant #native (#2236) important_document.exe
- Arguments:
- {"DesiredAccess":"0x100000","objectName":"CicLoadWinStaWinSta0","MutantHandle":"0x18f038"}
- Returned value:
- 0x0
- KernelBase.dll! OpenMutexW #sync (#2236) important_document.exe
- Arguments:
- {"lpName":"CicLoadWinStaWinSta0"}
- Returned value:
- 0x288
- ntdll.dll! NtOpenMutant #native (#2236) important_document.exe
- Arguments:
- {"DesiredAccess":"0x100000","objectName":"Local\\MSCTF.CtfMonitorInstMutexDefault1","MutantHandle":"0x18f244"}
- Returned value:
- 0x0
- KernelBase.dll! OpenMutexW #sync (#2236) important_document.exe
- Arguments:
- {"lpName":"Local\\MSCTF.CtfMonitorInstMutexDefault1"}
- Returned value:
- 0x288
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18f604","objectName":"SOFTWARE\\Microsoft\\CTF\\","DesiredAccess":"0x20019"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x850c0c","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\isWelcome.ini"}
- Returned value:
- null
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x853044","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\isWelcome.ini"}
- Returned value:
- null
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x850ba4","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\isWelcome.ini"}
- Returned value:
- null
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\InstallOptions.dll"}
- Returned value:
- 0xc0000034
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f8b4","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\InstallOptions.dll"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x0","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\InstallOptions.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0x288
- KernelBase.dll! CreateFileA #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x0","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\InstallOptions.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0x288
- KernelBase.dll! WriteFile #file (#2236) important_document.exe
- Arguments:
- {"nNumberOfBytesToWrite":"0x3a00","lpBuffer":"MZ�","lpNumberOfBytesWritten":"0x18f924","hFile":"0x288"}
- Returned value:
- 0x1
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\InstallOptions.dll"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f2a4","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\InstallOptions.dll"}
- Returned value:
- null
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\InstallOptions.dll"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f2a4","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\InstallOptions.dll"}
- Returned value:
- null
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\InstallOptions.dll"}
- Returned value:
- 0x0
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f700","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\InstallOptions.dll"}
- Returned value:
- null
- KernelBase.dll! LoadLibraryExA #misc (#2236) important_document.exe
- Arguments:
- {"lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\InstallOptions.dll"}
- Returned value:
- 0x10000000
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"initDialog","hModule":null}
- Returned value:
- 0x10002931
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x853044","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\isWelcome.ini"}
- Returned value:
- null
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x853044","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\isWelcome.ini"}
- Returned value:
- null
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x853044","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\isWelcome.ini"}
- Returned value:
- null
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x853044","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\isWelcome.ini"}
- Returned value:
- null
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x853044","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\isWelcome.ini"}
- Returned value:
- null
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x853044","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\isWelcome.ini"}
- Returned value:
- null
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x853044","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\isWelcome.ini"}
- Returned value:
- null
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x853044","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\isWelcome.ini"}
- Returned value:
- null
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x853044","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\isWelcome.ini"}
- Returned value:
- null
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x853044","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\isWelcome.ini"}
- Returned value:
- null
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x853044","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\isWelcome.ini"}
- Returned value:
- null
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x853044","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\isWelcome.ini"}
- Returned value:
- null
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x853044","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\isWelcome.ini"}
- Returned value:
- null
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x853044","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\isWelcome.ini"}
- Returned value:
- null
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x853044","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\isWelcome.ini"}
- Returned value:
- null
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x853044","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\isWelcome.ini"}
- Returned value:
- null
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x853044","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\isWelcome.ini"}
- Returned value:
- null
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x853044","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\isWelcome.ini"}
- Returned value:
- null
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x853044","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\isWelcome.ini"}
- Returned value:
- null
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x853044","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\isWelcome.ini"}
- Returned value:
- null
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x853044","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\isWelcome.ini"}
- Returned value:
- null
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x853044","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\isWelcome.ini"}
- Returned value:
- null
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x853044","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\isWelcome.ini"}
- Returned value:
- null
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x853044","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\isWelcome.ini"}
- Returned value:
- null
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x853044","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\isWelcome.ini"}
- Returned value:
- null
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x853044","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\isWelcome.ini"}
- Returned value:
- null
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x853044","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\isWelcome.ini"}
- Returned value:
- null
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x853044","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\isWelcome.ini"}
- Returned value:
- null
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x853044","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\isWelcome.ini"}
- Returned value:
- null
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x853044","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\isWelcome.ini"}
- Returned value:
- null
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x853044","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\isWelcome.ini"}
- Returned value:
- null
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x853044","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\isWelcome.ini"}
- Returned value:
- null
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x853044","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\isWelcome.ini"}
- Returned value:
- null
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x853044","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\isWelcome.ini"}
- Returned value:
- null
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x853044","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\isWelcome.ini"}
- Returned value:
- null
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x853044","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\isWelcome.ini"}
- Returned value:
- null
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x853044","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\isWelcome.ini"}
- Returned value:
- null
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x853044","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\isWelcome.ini"}
- Returned value:
- null
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x853044","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\isWelcome.ini"}
- Returned value:
- null
- ntdll.dll! NtOpenFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x853044","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\isWelcome.ini"}
- Returned value:
- null
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x853044","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\isWelcome.ini"}
- Returned value:
- null
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x853044","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\isWelcome.ini"}
- Returned value:
- null
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\Header.bmp"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f32c","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\Header.bmp"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x3","dwFlagsAndAttributes":"0x0","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\Header.bmp","dwDesiredAccess":"0x80000000","dwShareMode":"0x1"}
- Returned value:
- 0x294
- KernelBase.dll! GetFileSize #file (#2236) important_document.exe
- Arguments:
- {"lpFileSizeHigh":"0x11a","hFile":"0x294"}
- Returned value:
- null
- ntdll.dll! NtQueryAttributesFile #native (#2236) important_document.exe
- Arguments:
- {"objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\InstallOptions.dll"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18f8b4","objectName":"\\??\\C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\InstallOptions.dll"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\InstallOptions.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! CreateFileA #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x1","dwFlagsAndAttributes":"0x2020","lpFileName":"C:\\Users\\<USER>\\AppData\\Local\\Temp\\nsk1EC.tmp\\InstallOptions.dll","dwDesiredAccess":"0x40000000","dwShareMode":"0x1"}
- Returned value:
- 0xffffffff
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"show","hModule":null}
- Returned value:
- 0x1000298e
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"GetLayout","hModule":"gdi32.dll"}
- Returned value:
- 0x76f77c90
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"GdiRealizationInfo","hModule":"gdi32.dll"}
- Returned value:
- 0x76f78078
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"FontIsLinked","hModule":"gdi32.dll"}
- Returned value:
- 0x76f799e2
- KernelBase.dll! LoadLibraryExA #misc (#2236) important_document.exe
- Arguments:
- {"lpFileName":"ADVAPI32.dll"}
- Returned value:
- 0x77300000
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"RegOpenKeyExW","hModule":"kernel32.dll"}
- Returned value:
- 0x7731468d
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18ee18","objectName":"SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\FontLink\\SystemLink","DesiredAccess":"0x109"}
- Returned value:
- 0x0
- kernel32.dll! RegOpenKeyExW #registry (#2236) important_document.exe
- Arguments:
- {"hKey":"HKEY_LOCAL_MACHINE","ulOptions":"0x0","samDesired":"0x109","lpSubKey":"SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\FontLink\\SystemLink","phkResult":"0x294"}
- Returned value:
- 0x0
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"RegQueryInfoKeyW","hModule":"kernel32.dll"}
- Returned value:
- 0x773146e7
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"GetTextFaceAliasW","hModule":"gdi32.dll"}
- Returned value:
- 0x76f79a1c
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"RegEnumValueW","hModule":"kernel32.dll"}
- Returned value:
- 0x773148cc
- kernel32.dll! RegEnumValueW #registry (#2236) important_document.exe
- Arguments:
- {"hKey":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\DataStore_V1.0","dwIndex":"0x0","lpcbData":"0x0","lpReserved":"0x0","lpValueName":"MS PGothic MC","lpType":"0x0","lpData":null}
- Returned value:
- 0x0
- kernel32.dll! RegEnumValueW #registry (#2236) important_document.exe
- Arguments:
- {"hKey":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\DataStore_V1.0","dwIndex":"0x1","lpcbData":"0x0","lpReserved":"0x0","lpValueName":"Segoe Media Center","lpType":"0x0","lpData":null}
- Returned value:
- 0x0
- kernel32.dll! RegEnumValueW #registry (#2236) important_document.exe
- Arguments:
- {"hKey":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\DataStore_V1.0","dwIndex":"0x2","lpcbData":"0x0","lpReserved":"0x0","lpValueName":"Segoe Media Center Semibold","lpType":"0x0","lpData":null}
- Returned value:
- 0x0
- kernel32.dll! RegEnumValueW #registry (#2236) important_document.exe
- Arguments:
- {"hKey":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\DataStore_V1.0","dwIndex":"0x3","lpcbData":"0x0","lpReserved":"0x0","lpValueName":"Segoe Media Center Light","lpType":"0x0","lpData":null}
- Returned value:
- 0x0
- kernel32.dll! RegEnumValueW #registry (#2236) important_document.exe
- Arguments:
- {"hKey":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\DataStore_V1.0","dwIndex":"0x4","lpcbData":"0x0","lpReserved":"0x0","lpValueName":"Lucida Sans Unicode","lpType":"0x0","lpData":null}
- Returned value:
- 0x0
- kernel32.dll! RegEnumValueW #registry (#2236) important_document.exe
- Arguments:
- {"hKey":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\DataStore_V1.0","dwIndex":"0x5","lpcbData":"0x0","lpReserved":"0x0","lpValueName":"Microsoft Sans Serif","lpType":"0x0","lpData":null}
- Returned value:
- 0x0
- kernel32.dll! RegEnumValueW #registry (#2236) important_document.exe
- Arguments:
- {"hKey":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\DataStore_V1.0","dwIndex":"0x6","lpcbData":"0x0","lpReserved":"0x0","lpValueName":"Tahoma","lpType":"0x0","lpData":null}
- Returned value:
- 0x0
- kernel32.dll! RegEnumValueW #registry (#2236) important_document.exe
- Arguments:
- {"hKey":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\DataStore_V1.0","dwIndex":"0x7","lpcbData":"0x0","lpReserved":"0x0","lpValueName":"Segoe UI","lpType":"0x0","lpData":null}
- Returned value:
- 0x0
- kernel32.dll! RegEnumValueW #registry (#2236) important_document.exe
- Arguments:
- {"hKey":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\DataStore_V1.0","dwIndex":"0x8","lpcbData":"0x0","lpReserved":"0x0","lpValueName":"MingLiU","lpType":"0x0","lpData":null}
- Returned value:
- 0x0
- kernel32.dll! RegEnumValueW #registry (#2236) important_document.exe
- Arguments:
- {"hKey":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\DataStore_V1.0","dwIndex":"0x9","lpcbData":"0x0","lpReserved":"0x0","lpValueName":"PMingLiU","lpType":"0x0","lpData":null}
- Returned value:
- 0x0
- kernel32.dll! RegEnumValueW #registry (#2236) important_document.exe
- Arguments:
- {"hKey":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\DataStore_V1.0","dwIndex":"0xa","lpcbData":"0x0","lpReserved":"0x0","lpValueName":"MingLiU_HKSCS","lpType":"0x0","lpData":null}
- Returned value:
- 0x0
- kernel32.dll! RegEnumValueW #registry (#2236) important_document.exe
- Arguments:
- {"hKey":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\DataStore_V1.0","dwIndex":"0xb","lpcbData":"0x0","lpReserved":"0x0","lpValueName":"MingLiU-ExtB","lpType":"0x0","lpData":null}
- Returned value:
- 0x0
- kernel32.dll! RegEnumValueW #registry (#2236) important_document.exe
- Arguments:
- {"hKey":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\DataStore_V1.0","dwIndex":"0xc","lpcbData":"0x0","lpReserved":"0x0","lpValueName":"PMingLiU-ExtB","lpType":"0x0","lpData":null}
- Returned value:
- 0x0
- kernel32.dll! RegEnumValueW #registry (#2236) important_document.exe
- Arguments:
- {"hKey":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\DataStore_V1.0","dwIndex":"0xd","lpcbData":"0x0","lpReserved":"0x0","lpValueName":"MingLiU_HKSCS-ExtB","lpType":"0x0","lpData":null}
- Returned value:
- 0x0
- kernel32.dll! RegEnumValueW #registry (#2236) important_document.exe
- Arguments:
- {"hKey":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\DataStore_V1.0","dwIndex":"0xe","lpcbData":"0x0","lpReserved":"0x0","lpValueName":"Microsoft JhengHei","lpType":"0x0","lpData":null}
- Returned value:
- 0x0
- kernel32.dll! RegEnumValueW #registry (#2236) important_document.exe
- Arguments:
- {"hKey":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\DataStore_V1.0","dwIndex":"0xf","lpcbData":"0x0","lpReserved":"0x0","lpValueName":"Microsoft JhengHei Bold","lpType":"0x0","lpData":null}
- Returned value:
- 0x0
- kernel32.dll! RegEnumValueW #registry (#2236) important_document.exe
- Arguments:
- {"hKey":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\DataStore_V1.0","dwIndex":"0x10","lpcbData":"0x0","lpReserved":"0x0","lpValueName":"SimSun","lpType":"0x0","lpData":null}
- Returned value:
- 0x0
- kernel32.dll! RegEnumValueW #registry (#2236) important_document.exe
- Arguments:
- {"hKey":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\DataStore_V1.0","dwIndex":"0x11","lpcbData":"0x0","lpReserved":"0x0","lpValueName":"SimSun-ExtB","lpType":"0x0","lpData":null}
- Returned value:
- 0x0
- kernel32.dll! RegEnumValueW #registry (#2236) important_document.exe
- Arguments:
- {"hKey":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\DataStore_V1.0","dwIndex":"0x12","lpcbData":"0x0","lpReserved":"0x0","lpValueName":"NSimSun","lpType":"0x0","lpData":null}
- Returned value:
- 0x0
- kernel32.dll! RegEnumValueW #registry (#2236) important_document.exe
- Arguments:
- {"hKey":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\DataStore_V1.0","dwIndex":"0x13","lpcbData":"0x0","lpReserved":"0x0","lpValueName":"Microsoft YaHei","lpType":"0x0","lpData":null}
- Returned value:
- 0x0
- kernel32.dll! RegEnumValueW #registry (#2236) important_document.exe
- Arguments:
- {"hKey":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\DataStore_V1.0","dwIndex":"0x14","lpcbData":"0x0","lpReserved":"0x0","lpValueName":"Microsoft YaHei Bold","lpType":"0x0","lpData":null}
- Returned value:
- 0x0
- kernel32.dll! RegEnumValueW #registry (#2236) important_document.exe
- Arguments:
- {"hKey":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\DataStore_V1.0","dwIndex":"0x15","lpcbData":"0x0","lpReserved":"0x0","lpValueName":"Meiryo","lpType":"0x0","lpData":null}
- Returned value:
- 0x0
- kernel32.dll! RegEnumValueW #registry (#2236) important_document.exe
- Arguments:
- {"hKey":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\DataStore_V1.0","dwIndex":"0x16","lpcbData":"0x0","lpReserved":"0x0","lpValueName":"Meiryo Bold","lpType":"0x0","lpData":null}
- Returned value:
- 0x0
- kernel32.dll! RegEnumValueW #registry (#2236) important_document.exe
- Arguments:
- {"hKey":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\DataStore_V1.0","dwIndex":"0x17","lpcbData":"0x0","lpReserved":"0x0","lpValueName":"Meiryo UI","lpType":"0x0","lpData":null}
- Returned value:
- 0x0
- kernel32.dll! RegEnumValueW #registry (#2236) important_document.exe
- Arguments:
- {"hKey":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\DataStore_V1.0","dwIndex":"0x18","lpcbData":"0x0","lpReserved":"0x0","lpValueName":"Meiryo UI Bold","lpType":"0x0","lpData":null}
- Returned value:
- 0x0
- kernel32.dll! RegEnumValueW #registry (#2236) important_document.exe
- Arguments:
- {"hKey":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\DataStore_V1.0","dwIndex":"0x19","lpcbData":"0x0","lpReserved":"0x0","lpValueName":"MS Gothic","lpType":"0x0","lpData":null}
- Returned value:
- 0x0
- kernel32.dll! RegEnumValueW #registry (#2236) important_document.exe
- Arguments:
- {"hKey":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\DataStore_V1.0","dwIndex":"0x1a","lpcbData":"0x0","lpReserved":"0x0","lpValueName":"MS PGothic","lpType":"0x0","lpData":null}
- Returned value:
- 0x0
- kernel32.dll! RegEnumValueW #registry (#2236) important_document.exe
- Arguments:
- {"hKey":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\DataStore_V1.0","dwIndex":"0x1b","lpcbData":"0x0","lpReserved":"0x0","lpValueName":"MS UI Gothic","lpType":"0x0","lpData":null}
- Returned value:
- 0x0
- kernel32.dll! RegEnumValueW #registry (#2236) important_document.exe
- Arguments:
- {"hKey":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\DataStore_V1.0","dwIndex":"0x1c","lpcbData":"0x0","lpReserved":"0x0","lpValueName":"MS Mincho","lpType":"0x0","lpData":null}
- Returned value:
- 0x0
- kernel32.dll! RegEnumValueW #registry (#2236) important_document.exe
- Arguments:
- {"hKey":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\DataStore_V1.0","dwIndex":"0x1d","lpcbData":"0x0","lpReserved":"0x0","lpValueName":"MS PMincho","lpType":"0x0","lpData":null}
- Returned value:
- 0x0
- kernel32.dll! RegEnumValueW #registry (#2236) important_document.exe
- Arguments:
- {"hKey":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\DataStore_V1.0","dwIndex":"0x1e","lpcbData":"0x0","lpReserved":"0x0","lpValueName":"Batang","lpType":"0x0","lpData":null}
- Returned value:
- 0x0
- kernel32.dll! RegEnumValueW #registry (#2236) important_document.exe
- Arguments:
- {"hKey":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\DataStore_V1.0","dwIndex":"0x1f","lpcbData":"0x0","lpReserved":"0x0","lpValueName":"BatangChe","lpType":"0x0","lpData":null}
- Returned value:
- 0x0
- kernel32.dll! RegEnumValueW #registry (#2236) important_document.exe
- Arguments:
- {"hKey":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\DataStore_V1.0","dwIndex":"0x20","lpcbData":"0x0","lpReserved":"0x0","lpValueName":"Dotum","lpType":"0x0","lpData":null}
- Returned value:
- 0x0
- kernel32.dll! RegEnumValueW #registry (#2236) important_document.exe
- Arguments:
- {"hKey":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\DataStore_V1.0","dwIndex":"0x21","lpcbData":"0x0","lpReserved":"0x0","lpValueName":"DotumChe","lpType":"0x0","lpData":null}
- Returned value:
- 0x0
- kernel32.dll! RegEnumValueW #registry (#2236) important_document.exe
- Arguments:
- {"hKey":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\DataStore_V1.0","dwIndex":"0x22","lpcbData":"0x0","lpReserved":"0x0","lpValueName":"Gulim","lpType":"0x0","lpData":null}
- Returned value:
- 0x0
- kernel32.dll! RegEnumValueW #registry (#2236) important_document.exe
- Arguments:
- {"hKey":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\DataStore_V1.0","dwIndex":"0x23","lpcbData":"0x0","lpReserved":"0x0","lpValueName":"GulimChe","lpType":"0x0","lpData":null}
- Returned value:
- 0x0
- kernel32.dll! RegEnumValueW #registry (#2236) important_document.exe
- Arguments:
- {"hKey":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\DataStore_V1.0","dwIndex":"0x24","lpcbData":"0x0","lpReserved":"0x0","lpValueName":"Gungsuh","lpType":"0x0","lpData":null}
- Returned value:
- 0x0
- kernel32.dll! RegEnumValueW #registry (#2236) important_document.exe
- Arguments:
- {"hKey":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\DataStore_V1.0","dwIndex":"0x25","lpcbData":"0x0","lpReserved":"0x0","lpValueName":"GungsuhChe","lpType":"0x0","lpData":null}
- Returned value:
- 0x0
- kernel32.dll! RegEnumValueW #registry (#2236) important_document.exe
- Arguments:
- {"hKey":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\DataStore_V1.0","dwIndex":"0x26","lpcbData":"0x0","lpReserved":"0x0","lpValueName":"Malgun Gothic","lpType":"0x0","lpData":null}
- Returned value:
- 0x0
- kernel32.dll! RegEnumValueW #registry (#2236) important_document.exe
- Arguments:
- {"hKey":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\DataStore_V1.0","dwIndex":"0x27","lpcbData":"0x0","lpReserved":"0x0","lpValueName":"Malgun Gothic Bold","lpType":"0x0","lpData":null}
- Returned value:
- 0x0
- kernel32.dll! RegEnumValueW #registry (#2236) important_document.exe
- Arguments:
- {"hKey":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\DataStore_V1.0","dwIndex":"0x28","lpcbData":"0x0","lpReserved":"0x0","lpValueName":"","lpType":"0x0","lpData":null}
- Returned value:
- 0x103
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"RegCloseKey","hModule":"kernel32.dll"}
- Returned value:
- 0x7731469d
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18eaac","objectName":"SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\DataStore_V1.0","DesiredAccess":"0x101"}
- Returned value:
- 0x0
- kernel32.dll! RegOpenKeyExW #registry (#2236) important_document.exe
- Arguments:
- {"hKey":"HKEY_LOCAL_MACHINE","ulOptions":"0x0","samDesired":"0x101","lpSubKey":"SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\DataStore_V1.0","phkResult":"0x294"}
- Returned value:
- 0x0
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"RegQueryValueExW","hModule":"kernel32.dll"}
- Returned value:
- 0x773146ad
- kernel32.dll! RegQueryValueExW #registry (#2236) important_document.exe
- Arguments:
- {"hKey":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\DataStore_V1.0","lpData":"","lpcbData":"0x18eaa0","lpType":"0x18eaa8","lpValueName":"Disable"}
- Returned value:
- 0x2
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"RegQueryValueExW","hModule":"kernel32.dll"}
- Returned value:
- 0x773146ad
- kernel32.dll! RegQueryValueExW #registry (#2236) important_document.exe
- Arguments:
- {"hKey":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\DataStore_V1.0","lpData":"C:\\Windows\\Fonts\\staticcache.dat","lpcbData":"0x18eaa0","lpType":"0x18eaa8","lpValueName":"DataFilePath"}
- Returned value:
- 0x0
- ntdll.dll! NtCreateFile #native (#2236) important_document.exe
- Arguments:
- {"FileHandle":"0x18e9d8","objectName":"\\??\\C:\\Windows\\Fonts\\staticcache.dat"}
- Returned value:
- null
- KernelBase.dll! CreateFileW #file (#2236) important_document.exe
- Arguments:
- {"lpSecurityAttributes":"0x0","dwCreationDisposition":"0x3","dwFlagsAndAttributes":"0x0","lpFileName":"C:\\Windows\\Fonts\\staticcache.dat","dwDesiredAccess":"0x80000000","dwShareMode":"0x5"}
- Returned value:
- 0x294
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"GetFontAssocStatus","hModule":"gdi32.dll"}
- Returned value:
- 0x76f79a02
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18f24c","objectName":"SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback","DesiredAccess":"0x101"}
- Returned value:
- 0x0
- kernel32.dll! RegOpenKeyExW #registry (#2236) important_document.exe
- Arguments:
- {"hKey":"HKEY_LOCAL_MACHINE","ulOptions":"0x0","samDesired":"0x101","lpSubKey":"SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback","phkResult":"0x2a0"}
- Returned value:
- 0x0
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"RegQueryValueExA","hModule":"kernel32.dll"}
- Returned value:
- 0x773148ef
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18f24c","objectName":"SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback","DesiredAccess":"0x109"}
- Returned value:
- 0x0
- kernel32.dll! RegOpenKeyExW #registry (#2236) important_document.exe
- Arguments:
- {"hKey":"HKEY_LOCAL_MACHINE","ulOptions":"0x0","samDesired":"0x109","lpSubKey":"SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback","phkResult":"0x2a0"}
- Returned value:
- 0x0
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"RegEnumKeyExW","hModule":"kernel32.dll"}
- Returned value:
- 0x773146c8
- kernel32.dll! RegEnumKeyExW #registry (#2236) important_document.exe
- Arguments:
- {"hKey":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback","dwIndex":"0x0","lpReserved":"0x0","lpcName":"\u0007","lpName":"MingLiU"}
- Returned value:
- 0x0
- kernel32.dll! RegEnumKeyExW #registry (#2236) important_document.exe
- Arguments:
- {"hKey":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback","dwIndex":"0x1","lpReserved":"0x0","lpcName":"\r","lpName":"MingLiU_HKSCS"}
- Returned value:
- 0x0
- kernel32.dll! RegEnumKeyExW #registry (#2236) important_document.exe
- Arguments:
- {"hKey":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback","dwIndex":"0x2","lpReserved":"0x0","lpcName":"\b","lpName":"PMingLiU"}
- Returned value:
- 0x0
- kernel32.dll! RegEnumKeyExW #registry (#2236) important_document.exe
- Arguments:
- {"hKey":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback","dwIndex":"0x3","lpReserved":"0x0","lpcName":"\u0006","lpName":"SimSun"}
- Returned value:
- 0x0
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"GetTextFaceAliasW","hModule":"gdi32.dll"}
- Returned value:
- 0x76f79a1c
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18f244","objectName":"MS Shell Dlg 2","DesiredAccess":"0x101"}
- Returned value:
- 0xc0000034
- kernel32.dll! RegOpenKeyExW #registry (#2236) important_document.exe
- Arguments:
- {"hKey":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback","ulOptions":"0x0","samDesired":"0x101","lpSubKey":"MS Shell Dlg 2","phkResult":"0x0"}
- Returned value:
- 0x2
- KernelBase.dll! GetProcAddress #misc (#2236) important_document.exe
- Arguments:
- {"lpProcName":"GdiIsMetaPrintDC","hModule":"gdi32.dll"}
- Returned value:
- 0x76f79068
- ntdll.dll! NtOpenKeyEx #native (#2236) important_document.exe
- Arguments:
- {"OpenOptions":"0x0","KeyHandle":"0x18f120","objectName":"SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback","DesiredAccess":"0x109"}
- Returned value:
- 0x0
- v1.2.0
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement